I was trying to schedule an alert which should trigger only once.
i'm giving the cron schedule as */35 2 * * *
(which means it should trigger an alert at 2:35 am when the condition is met. )
but the alert is trigger twice i.e at 2:01 and 2:35.
You want to run only once per day (based on what you have)? If yes then use like this 35 2 * * *
Use this site to test cron https://crontab.guru/
You want to run only once per day (based on what you have)? If yes then use like this 35 2 * * *
Use this site to test cron https://crontab.guru/
I have one more doubt, I have scheduled one of my saved search at 4:30 EST, but it triggered an alert at 8:42 EST.
Run this search and see what is the dispatch time and scheduled time for your alert search
index=_internal sourcetype=scheduler savedsearch_name="Your ALert Search Name here" status=success
| table _time *_time | convert ctime(*_time)
Thank you, the crontab.guru is very helpful .