Splunk Search

Setting up multiple cron job to the same alert

lanilim16
Explorer

How do I add multiple cron jobs given 1 alert? I have to setup alert traffic by customer, if there are none for the last 15 minutes for example send an alert, however during non-business hours (ie. 1AM-3AM or weekends), just have to check every hour then send an alert. Is this at all possible without duplicating the alert?

Tags (3)
0 Karma

stephanefotso
Motivator

Hello!
I'm sorry, but that is not yet possible with splunk without duplicating alerts! Means,
- One alert for the 15 minutes there are no customers
- One alert cron at 1AM-3AM
- One alert for the weekends

Thanks

SGF
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...