Create scheduled alerts
Create a scheduled alert to search for events on a regular schedule. You can configure scheduling, trigger conditions, and throttling to customize the alert.
Using cron expressions
You can use a cron expression to customize alert scheduling. See Use cron expressions for scheduling to learn more.
Create a scheduled alert
- Navigate to the Search page in the Search and Reporting app.
- Create a search.
- Select Save As>Alert.
- Enter a title and optional description.
- Specify permissions.
- Configure alert scheduling. There are two options for scheduling.
Option Next steps for this option Select one of the available scheduling options and set a time. None. For further customization, select Run on Cron Schedule to use a time range and cron expression.
- Enter the Earliest and Latest values for the search time range. These values override the original search time range. To avoid overlaps or gaps, the execution schedule should match the search time range. For example, to run a search every 20 minutes the search time range should also be 20 minutes (-20m).
- Enter a cron expression to schedule the search. See cron expression examples below.
- Configure trigger conditions.
- (Optional) Configure a trigger throttling period.
- Select one or more alert actions that should happen when the alert triggers.
- Click Save.
Alert type and triggering scenarios
Use cron expressions for scheduling
This documentation applies to the following versions of Splunk® Enterprise: 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.5.0, 6.5.1, 6.5.1612 (Splunk Cloud only), 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.6.0, 6.6.1, 6.6.2, 6.6.3, 7.0.0