Interesting question. I'm not sure that you can with Splunk's cron notation. If the search doesn't consume many resources, just run it every hour. Otherwise I suppose you could:
Make a saved search
Use cron or a bash script on a linux host to run saved/searches/{name}/dispatch
http://docs.splunk.com/Documentation/Splunk/6.3.1511/RESTREF/RESTsearch#saved.2Fsearches.2F.7Bname.7D.2Fdispatch
Check out http://stackoverflow.com/questions/1417098/cronjob-every-25-hours
I'm curious: what use case do you have for this search?
... View more