Splunk Search

How to set a report hourly for time frame between 26th to 5th of each month?

wanda619
Path Finder

How to set a report hourly for time frame between 26th to 5th of each month?

Labels (3)
0 Karma

johnhuang
Motivator

Unclear if you want to schedule your report or filter your data using those dates.

 

The following cron schedule/expression will schedule your report to run every hour between those dates:

 

 

0 * 1-5,26-31 * *

 

 

If you're looking to filter the data in your search to only include those date: 

 

| eval dayofmonth=strftime(_time, "%e")
| search dayofmonth>25 OR dayofmonth<6

 

 

wanda619
Path Finder

@johnhuang  if we want to set the alert for 365 days a year,  hourly? how to acheive that?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

0 * * * *

this will run alert on every hour on every day including those years which have something else than 365 days.

You could test these on  https://crontab.guru/#0_*_*_*_*

r. Ismo

wanda619
Path Finder

@isoutamo is their a way to limit this alert once per day? I tried using throttle and supressing it for once a day.  is thier some other way? 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

If you want check it only once a day just switch wanted hour to the second * like

0 10 * * *

You should test these with https://crontab.guru/ which told to you what those are meaning.

0 Karma

jdunlea
Contributor

Set your cron scheduled as follows for the scheduled report and it should work.

 

0 */1 1,2,3,4,5,26,27,28,29,30,31 * *

wanda619
Path Finder

@jdunlea if we want to set the alert for 365 days a year,  hourly? how to acheive that?

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...