Alerting

How to write Cron Expression for a scheduled alert?

gpunjabi
New Member

I want help writing a Cron Expression for a scheduled alert to start my search query at 2:45 AM for every 10 mins till 5:55 AM.

My Cron would run like first at 2:45,2:55,3:05,3:15.....5:55.

Can anyone please help me?

0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi,

As far as I know you can't achieve this with single cron but you can schedule same search twice with 2 different cron.

First cron 45-59/10 2 * * *, this cron executes at 02:45 and 02:55

Second cron 5-59/10 3-5 * * * , this cron executes from 03:05, 03:15 to 05:55

View solution in original post

harsmarvania57
Ultra Champion

Hi,

As far as I know you can't achieve this with single cron but you can schedule same search twice with 2 different cron.

First cron 45-59/10 2 * * *, this cron executes at 02:45 and 02:55

Second cron 5-59/10 3-5 * * * , this cron executes from 03:05, 03:15 to 05:55

gpunjabi
New Member

Thanks Harshmarvania 🙂

0 Karma

nainanayana
New Member

i want give schedule alert for last day of ever month, can we please help me how to write cron expression for this or else any other way to do

0 Karma

harsmarvania57
Ultra Champion

Welcome @gpunjabi

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...