NetLabToolsNetLabTools

Cron syntax explained: examples for every use case

Cron expressions step by step — with 10 real-world examples from every-minute to the last Friday of the month.

6 min read

Cron has been the Unix standard for scheduled jobs for decades — and every developer forgets the field order at least once per quarter. This article walks through the syntax and 10 examples you can use directly. To test expressions interactively, see our cron parser.

Anatomy of a cron expression

A classic crontab has five fields separated by spaces:

*  *  *  *  *
|  |  |  |  |
|  |  |  |  +----- day of week  (0-6, Sunday = 0 or 7)
|  |  |  +-------- month        (1-12)
|  |  +----------- day of month (1-31)
|  +-------------- hour         (0-23)
+----------------- minute       (0-59)

Special characters

  • * – any value
  • , – list: 1,15,30
  • - – range: 9-17
  • / – step: */5 means "every 5th"
  • ? – "don't care" (Quartz/AWS only, not standard cron)

10 practical examples

ExpressionMeaningUse case
* * * * *Every minuteHeartbeat, health check
*/5 * * * *Every 5 minutesPolling external APIs
15 * * * *Hourly at :15Cache invalidation
30 2 * * *Daily at 02:30Nightly backup
0 9 * * 1-5Weekdays 9:00 AMDaily standup reminder
0 0 * * 0Sunday midnightWeekly report
0 0 1 * *First day of month, 00:00Monthly billing run
0 23 * * 5Every Friday 23:00Weekend deploy freeze
*/15 9-17 * * 1-5Every 15 min, 9–5, Mon–FriBusiness-hours sync
0 */6 * * *Every 6 hoursIndex rebuild

"Last Friday of the month" – not trivial

Standard cron can't express this directly. In Quartz you'd write 0 0 0 ? * 6L (L = last). With plain crontab you need a workaround: run every Friday at midnight, then check inside the script whether today is the last Friday — exit early if not:

0 0 * * 5  [ "$(date -d '+7 days' +\%m)" != "$(date +\%m)" ] && /path/to/job.sh

Common pitfalls

Day-of-month AND day-of-week

If you set both fields, they are combined with OR, not AND.0 0 1 * 1 runs on the 1st of every month or every Monday — not only on a 1st that is a Monday. This is one of the most common cron bugs.

Time zones

Most cron daemons run in the server's time zone, often UTC. If your backup should run "at 3 AM", check whether that's UTC or local time. During DST transitions a job may run twice or not at all — avoid scheduling between 02:00 and 03:00 local time.

6 fields with seconds

Quartz, Spring @Scheduled, AWS EventBridge and others use 6 fields with seconds in front:0 0 12 * * ?= daily at 12:00:00. If you copy a 5-field expression into a 6-field system, the job runs "every second of the X-th Y..." — a classic production bug.

Readable aliases

Many cron dialects support aliases: @hourly, @daily, @weekly, @monthly, @yearly, @reboot. They're a readability win for maintenance-heavy crontabs but aren't available everywhere.