Splunk Search

How to set an alert running every day hourly?

wanda619
Path Finder

how to set an alert running every day hourly?

ex - if new transactions /events occur alert the user

Labels (3)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please describe your use case some more, please.

The Splunk alert UI offers a dropdown to select "hourly" as a run interval.  How does that not meet your needs?

---
If this reply helps you, Karma would be appreciated.

wanda619
Path Finder

@richgalloway I want to set up an automated alert on the report , i guess we can use cron expression but not sure how

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The alert definition menu has a dropdown for the run interval.  The last entry in the dropdown lets you specify a cron schedule for the alert.  This is a set of 5 numbers, number ranges, and/or number lists that tell Splunk when to run the alert.  I won't go into a full description of cron, but you can visit https://crontab.guru for assistance with generating a cron schedule.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...