Splunk Search

How to set a report hourly for time frame between 26th to 5th of each month?

wanda619
Path Finder

How to set a report hourly for time frame between 26th to 5th of each month?

Labels (3)
0 Karma

johnhuang
Motivator

Unclear if you want to schedule your report or filter your data using those dates.

 

The following cron schedule/expression will schedule your report to run every hour between those dates:

 

 

0 * 1-5,26-31 * *

 

 

If you're looking to filter the data in your search to only include those date: 

 

| eval dayofmonth=strftime(_time, "%e")
| search dayofmonth>25 OR dayofmonth<6

 

 

wanda619
Path Finder

@johnhuang  if we want to set the alert for 365 days a year,  hourly? how to acheive that?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

0 * * * *

this will run alert on every hour on every day including those years which have something else than 365 days.

You could test these on  https://crontab.guru/#0_*_*_*_*

r. Ismo

wanda619
Path Finder

@isoutamo is their a way to limit this alert once per day? I tried using throttle and supressing it for once a day.  is thier some other way? 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

If you want check it only once a day just switch wanted hour to the second * like

0 10 * * *

You should test these with https://crontab.guru/ which told to you what those are meaning.

0 Karma

jdunlea
Contributor

Set your cron scheduled as follows for the scheduled report and it should work.

 

0 */1 1,2,3,4,5,26,27,28,29,30,31 * *

wanda619
Path Finder

@jdunlea if we want to set the alert for 365 days a year,  hourly? how to acheive that?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...