Splunk Search

Setting up multiple cron job to the same alert

lanilim16
Explorer

How do I add multiple cron jobs given 1 alert? I have to setup alert traffic by customer, if there are none for the last 15 minutes for example send an alert, however during non-business hours (ie. 1AM-3AM or weekends), just have to check every hour then send an alert. Is this at all possible without duplicating the alert?

Tags (3)
0 Karma

stephanefotso
Motivator

Hello!
I'm sorry, but that is not yet possible with splunk without duplicating alerts! Means,
- One alert for the 15 minutes there are no customers
- One alert cron at 1AM-3AM
- One alert for the weekends

Thanks

SGF
0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...