Hi mkrishnamoorthy,
Your cron schedule looks almost right (I'm sure it's the HTML dropping the * character.)
*/15 06-20 * * * will run the search starting from 6AM through 8PM every day of the year.
In the schedule, when you select time range, that's the range of time that Splunk searches from. So if you set it to last 15 minutes, at 6AM Splunk will run the search looking at 5:45AM - 6:00AM for the requested data.
The other way to approach this would be to create an alert that only fires if there are results, and then craft your search to check the time and only present results if the time falls within your scope of 6AM - 8PM.
... View more