Alerting

SUGGESTION: test and Translate CRONTAB in alert

rsennett_splunk
Splunk Employee
Splunk Employee

Splunk recommends as a Best Practice that real-time alerts be converted to "smallest reasonable repetition" so as to better manage resources. (real time takes a core and does not give it back). In line with that recommendation it would be helpful to make using the more granular "CRONTAB" notation easier to use by putting a bit of intelligence behind that text box.

At minimum testing the validity before allowing someone to save
At maximum, intelligently suggesting examples. (CRONTAB syntax is not likely to change without us knowing)

Resources like https://crontabguru.com are wonderful - but we should at least take the bullets out of the gun.

With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!
Tags (1)

ssadanala1
Contributor

Splunk has capability of testing and translating the crontab after you save the alert .
Once saved , the cron tab is been translated and show the time in "Next Scheduled Time". Thats how I usually I validate the cron tab .

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...