Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

A cron expression is a schedule, not a task. In the standard Unix crontab format it is five whitespace-separated fields that describe which calendar times match: minute, hour, day of month, month, and day of week. The command that actually runs is written after those five fields in a crontab line. For example, */5 * * * * means “at every minute that is a multiple of five,” which is 0, 5, 10 and so on through each hour.

The phrase “cron expression” is also used by cloud services and libraries that use different field counts, ranges, and special characters. The reading below follows Cronie, the crontab implementation used on many Linux systems, and the POSIX definition of the crontab format. Other schedulers are covered in the dialect section.

The five fields and their allowed values

Read a standard crontab schedule from left to right. Each position controls one part of the calendar, and a time runs only when the fields match together.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Position Field Accepted values (Cronie) Notes
1 Minute 0–59 Minute within the hour
2 Hour 0–23 Hour of the day, 24-hour clock
3 Day of month 1–31 Calendar day
4 Month 1–12 Cronie also accepts month names
5 Day of week 0–7 0 or 7 is Sunday; Cronie also accepts weekday names

Note that the day-of-week range runs to 7 in Cronie, not 6. Older or stricter implementations may not accept 7, so check the local manual page before relying on it.

Where the command fits

An expression on its own does nothing. A user crontab line adds a command after the five schedule fields:

30 4 * * * /usr/local/bin/backup.sh

System crontab files, such as /etc/crontab and files in /etc/cron.d, add a username between the schedule and the command:

Rank #2
Funny Planner Scheduler Job Title T-Shirt, Men, Black, Small
  • Show your love for funny sayings with this cute tee. Anyone with a great sense of humor will smile every time they put on this Funny Planner Scheduler Job Title look
  • A great gift for birthdays, Christmas or the holidays - surprise a friend or family member who loves a good laugh with something fun and personal
  • Lightweight, Classic fit, Double-needle sleeve and bottom hem
30 4 * * * root /usr/local/bin/backup.sh

POSIX describes the command field as executed by sh. Cronie documents that the command runs under /bin/sh unless the crontab sets a different shell. The line above therefore runs every day at 4:30 a.m. in the daemon’s local time, under the shell rules for that system.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the operators work

Each field accepts the same small set of operators:

Rank #3
Scheduler Funny Job Title Worker American Flag Scheduler T-Shirt
  • Funny Scheduler American Flag Design For Men And Women
  • Lightweight, Classic fit, Double-needle sleeve and bottom hem
  • * matches every allowed value in that field.
  • 5 selects one value.
  • 1,15 selects both listed values.
  • 1-5 selects an inclusive range.
  • */15 selects every fifteenth value within the field, starting from its first allowed value. In the minute field that means minutes 0, 15, 30, and 45.
  • 0-23/2 selects every other hour across the stated range.

A step counts values inside a field, not elapsed time

The slash does not create a repeating interval that runs across hour or day boundaries. It only selects positions inside the field. In Cronie, 0/35 in the minute field means minutes 0 and 35 of each hour, not an event every 35 minutes of continuous time. Likewise, */23 in the hour field matches hours 0 and 23 of each day, so it does not run every 23 hours. If you need a true elapsed interval, a crontab schedule is the wrong tool; use a service-level timer or a loop in a script.

Worked examples

These readings use Cronie’s five-field crontab syntax.

Expression Plain-language reading
* * * * * Every minute
*/5 * * * * Every five minutes: minutes 0, 5, 10, and so on, in every hour
0 2 * * * At 2:00 a.m. every day
0 9 * * 1-5 At 9:00 a.m. Monday through Friday
15 14 1 * * At 2:15 p.m. on the first day of each month
30 4 1,15 * 5 At 4:30 a.m. on the 1st and the 15th, and also on every Friday (see the day-field rule below)

Why a job runs on both the day of month and the weekday

This is the most common surprise. When both the day-of-month field and the day-of-week field are restricted, Cronie (and POSIX) treat them as alternatives: a day matches if either field matches. The minute, hour, and month fields must still match as well.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Take 0 9 13 * 5. It does not run only on Friday the 13th. It runs at 9:00 a.m. on the 13th of every month and also at 9:00 a.m. on every Friday. If you want Friday the 13th only, a single crontab line cannot express it directly; a script that checks the date is the usual workaround.

When one of the two day fields is *, only the other field decides the day. So 0 9 * * 5 runs every Friday and nothing else.

Time zones and daylight-saving changes

  • Cronie examines entries every minute. Its manual states: “cron(8) examines cron entries every minute.”
  • During the spring clock change, a local time that does not exist will not match, so a job scheduled inside the skipped hour does not run that day.
  • During the autumn change, a local time that occurs twice can match twice.
  • Cronie’s CRON_TZ setting selects the timezone used to interpret the schedule, but log timestamps are written in the daemon’s local timezone. Check both when you debug a job that seems to run at the wrong hour.

These behaviours are documented for Cronie. Other cron implementations, and other schedulers that borrow the word “cron,” may handle daylight-saving time differently.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Cron dialects differ

There is no single expression grammar. Identify the scheduler before you copy an expression from a tutorial, a forum post, or an AI assistant’s output.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Scheduler and reference Fields documented Weekday and special characters Timezone behaviour
Unix crontab (POSIX; Cronie crontab(5)) Five: minute, hour, day of month, month, day of week Cronie: 0 or 7 for Sunday, names accepted. Stepped and list operators as described above Daemon’s local time; Cronie’s CRON_TZ sets the schedule timezone
AWS CloudWatch recurring schedule Written as cron(Minutes Hours Day-of-month Month Day-of-week) Not covered here; consult the current AWS reference for weekday numbering and special characters UTC when no timezone is specified; named timezone identifiers are an option
Apache Log4j cron expressions Six required fields, starting with seconds, plus an optional year Special characters including ?, L, W, and #, which are not part of the basic POSIX description Not covered here; consult the Log4j reference for the time zone used by the trigger

A six-field expression pasted into a five-field crontab will be rejected or misread, and a five-field expression copied into a scheduler that expects seconds will fire at the wrong time. Cloud schedulers also often default to UTC rather than the host’s local time, which can shift a job by several hours.

Checking an expression before you rely on it

  1. Identify the scheduler. If the line sits in a user crontab edited with crontab -e and listed with crontab -l, you are working with the five-field Unix format.
  2. Count the fields. Five fields plus a command means a user crontab; five fields plus a username plus a command means a system file such as /etc/crontab.
  3. Check the day fields. If both the day of month and the weekday are restricted, expect OR matching and read the result as two sets of days.
  4. Confirm the timezone. Note whether the scheduler uses the host’s local time, UTC, or a named timezone, and whether a daylight-saving change falls near the scheduled hour.
  5. Verify with a first run. Watch the log after the first scheduled time, and remember that Cronie’s log timestamps follow the daemon’s local timezone.

Reading an expression takes less effort than debugging a job that fired on the wrong days. Most surprises come from the day-field rule, a mismatched field count, or an unexpected timezone, and each of those can be checked before the job goes live.

Quick Recap

Bestseller No. 2
Funny Planner Scheduler Job Title T-Shirt, Men, Black, Small
Funny Planner Scheduler Job Title T-Shirt, Men, Black, Small
Lightweight, Classic fit, Double-needle sleeve and bottom hem
$19.99
Bestseller No. 3
Scheduler Funny Job Title Worker American Flag Scheduler T-Shirt
Scheduler Funny Job Title Worker American Flag Scheduler T-Shirt
Funny Scheduler American Flag Design For Men And Women; Lightweight, Classic fit, Double-needle sleeve and bottom hem
$19.98

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.