Hi All,
I have a requirement where i want to setup the alert to run every 10 min on friday between 8-10pm and every 10 min on sunday between 6-8am.
i tried writing the Cron for it however it didnt work
Can you please help
15 20-22,6-8 * * 5,0 this is Cron schedule we have used but it is running during the same time on Friday and Sunday
Which is to be expected with the given cron schedule. Running at different times on certain days requires multiple cron schedules. Since Splunk supports a single cron schedule for an alert, you need a separate alert for each cron schedule. Or, as suggested by @JacekF , you can add intelligence to the alert.
I don't think this can be done with a cron schedule only. You can use a cron similar to that one:
*/10 20-22,6-8 * * 5,0
This should execute the alert at every 10th minute past every hour from 20 through 22 and every hour from 6 through 8 on Friday and Sunday. In the SPL you can add a condition to check the day of week and the hour and return results depending on day/hour combination.
It would help to know the cron schedule(s) you tried, but I think you'll need two alerts to accomplish that.