<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to setup an alert but omit certain time of day? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-setup-an-alert-but-omit-certain-time-of-day/m-p/644348#M223174</link>
    <description>&lt;P&gt;Hello All,&lt;/P&gt;
&lt;P&gt;I'm trying to do a search&amp;nbsp;"found ANC VITC in source 01:00:00;00" which works just fine, but I would like to omit these errors from the UTC times of 01:00:00;00 - 01:00:00;05 because between those times the 01:00:00;00 timecode is legit.&amp;nbsp; Is this possible?&lt;/P&gt;
&lt;P&gt;A co-worker believes there is a result object "called_time" but I'm unclear of the syntax use.&lt;/P&gt;</description>
    <pubDate>Wed, 24 May 2023 08:35:30 GMT</pubDate>
    <dc:creator>ScottW1</dc:creator>
    <dc:date>2023-05-24T08:35:30Z</dc:date>
    <item>
      <title>How to setup an alert but omit certain time of day?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-setup-an-alert-but-omit-certain-time-of-day/m-p/644348#M223174</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;
&lt;P&gt;I'm trying to do a search&amp;nbsp;"found ANC VITC in source 01:00:00;00" which works just fine, but I would like to omit these errors from the UTC times of 01:00:00;00 - 01:00:00;05 because between those times the 01:00:00;00 timecode is legit.&amp;nbsp; Is this possible?&lt;/P&gt;
&lt;P&gt;A co-worker believes there is a result object "called_time" but I'm unclear of the syntax use.&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 08:35:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-setup-an-alert-but-omit-certain-time-of-day/m-p/644348#M223174</guid>
      <dc:creator>ScottW1</dc:creator>
      <dc:date>2023-05-24T08:35:30Z</dc:date>
    </item>
    <item>
      <title>Re: Setup an alert but omit certain time of day</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-setup-an-alert-but-omit-certain-time-of-day/m-p/644363#M223182</link>
      <description>&lt;P&gt;Please share your current search&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2023 22:45:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-setup-an-alert-but-omit-certain-time-of-day/m-p/644363#M223182</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-05-23T22:45:43Z</dc:date>
    </item>
    <item>
      <title>Re: Setup an alert but omit certain time of day</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-setup-an-alert-but-omit-certain-time-of-day/m-p/645583#M223519</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;, apologies for the delayed response.&amp;nbsp; Here is the current search:&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;index=morpheus6* "Found ANC VITC in source 01:00:00;00"&lt;/P&gt;&lt;P&gt;It produced the following results today:&lt;/P&gt;&lt;P&gt;6/2/23&lt;BR /&gt;2:30:00.000 PM&lt;BR /&gt;"2023-06-02 14:30:00;05","ICER43","BA69","Information","REC246","Found ANC VITC in source 01:00:00;00"&lt;BR /&gt;host = DEN-6XMR-ICER43source = C:\Logs\2023-06-02_XREC43.logsourcetype = ICERLog&lt;BR /&gt;6/2/23&lt;BR /&gt;2:30:00.000 PM&lt;BR /&gt;"2023-06-02 14:30:00;03","ICER43","7DAA","Information","REC246","Found ANC VITC in source 01:00:00;00"&lt;BR /&gt;host = DEN-6YMR-ICER43source = C:\Logs\2023-06-02_YREC43.logsourcetype = ICERLog&lt;BR /&gt;6/2/23&lt;BR /&gt;1:30:00.000 PM&lt;BR /&gt;"2023-06-02 13:30:00;03","REC241_242","78DE","Information","REC242","Found ANC VITC in source 01:00:00;00"&lt;BR /&gt;host = DEN-6XMR-ICER41source = C:\Logs\2023-06-02_XREC41.logsourcetype = ICERLog&lt;BR /&gt;6/2/23&lt;BR /&gt;1:00:00.000 PM&lt;BR /&gt;"2023-06-02 13:00:00;03","REC241_242","70E5","Information","REC241","Found ANC VITC in source 01:00:00;00"&lt;BR /&gt;host = DEN-6XMR-ICER41source = C:\Logs\2023-06-02_XREC41.logsourcetype = ICERLog&lt;BR /&gt;6/2/23&lt;BR /&gt;3:00:00.000 AM&lt;BR /&gt;"2023-06-02 03:00:00;03","REC241_242","2A01","Information","REC242","Found ANC VITC in source 01:00:00;00"&lt;BR /&gt;host = DEN-6XMR-ICER41source = C:\Logs\2023-06-02_XREC41.logsourcetype = ICERLog&lt;BR /&gt;6/2/23&lt;BR /&gt;2:00:00.000 AM&lt;BR /&gt;"2023-06-02 02:00:00;03","REC241_242","FF28","Information","REC241","Found ANC VITC in source 01:00:00;00"&lt;BR /&gt;host = DEN-6XMR-ICER41source = C:\Logs\2023-06-02_XREC41.logsourcetype = ICERLog&lt;BR /&gt;6/2/23&lt;BR /&gt;1:00:00.000 AM&lt;BR /&gt;"2023-06-02 01:00:00;03","ICER61","FE44","Information","REC261","Found ANC VITC in source 01:00:00;00"&lt;BR /&gt;host = DEN-6XMR-ICER61source = C:\Logs\2023-06-02_XREC61.logsourcetype = ICERLog&lt;BR /&gt;6/2/23&lt;BR /&gt;1:00:00.000 AM&lt;BR /&gt;"2023-06-02 01:00:00;02","REC241_242","F70F","Information","REC242","Found ANC VITC in source 01:00:00;00"&lt;BR /&gt;host = DEN-6XMR-ICER41source = C:\Logs\2023-06-02_XREC41.logsourcetype = ICERLog&lt;BR /&gt;6/2/23&lt;BR /&gt;1:00:00.000 AM&lt;BR /&gt;"2023-06-02 01:00:00;03","ICER62","C2DE","Information","REC266","Found ANC VITC in source 01:00:00;00"&lt;BR /&gt;host = DEN-6XMR-ICER62source = C:\Logs\2023-06-02_XREC62.logsourcetype = ICERLog&lt;BR /&gt;6/2/23&lt;BR /&gt;1:00:00.000 AM&lt;BR /&gt;"2023-06-02 01:00:00;03","ICER61","68BC","Information","REC261","Found ANC VITC in source 01:00:00;00"&lt;BR /&gt;host = DEN-6YMR-ICER61source = C:\Logs\2023-06-02_YREC61.logsourcetype = ICERLog&lt;BR /&gt;6/2/23&lt;BR /&gt;1:00:00.000 AM&lt;BR /&gt;"2023-06-02 01:00:00;03","ICER62","EA99","Information","REC266","Found ANC VITC in source 01:00:00;00"&lt;BR /&gt;host = DEN-6YMR-ICER62source = C:\Logs\2023-06-02_YREC62.logsourcetype = ICERLog&lt;BR /&gt;6/1/23&lt;BR /&gt;11:00:00.000 PM&lt;BR /&gt;"2023-06-01 23:00:00;03","REC241_242","F2EB","Information","REC241","Found ANC VITC in source 01:00:00;00"&lt;BR /&gt;host = DEN-6XMR-ICER41source = C:\Logs\2023-06-01_XREC41.logsourcetype = ICERLog&lt;BR /&gt;6/1/23&lt;BR /&gt;9:00:00.000 PM&lt;BR /&gt;"2023-06-01 21:00:00;03","REC241_242","DA8F","Information","REC242","Found ANC VITC in source 01:00:00;00"&lt;BR /&gt;host = DEN-6XMR-ICER41source = C:\Logs\2023-06-01_XREC41.logsourcetype = ICERLog&lt;/P&gt;&lt;P&gt;The ones at 01:00:00;00 to 01:00:00;03 are legit.&amp;nbsp; The others are errors.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2023 16:44:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-setup-an-alert-but-omit-certain-time-of-day/m-p/645583#M223519</guid>
      <dc:creator>ScottW1</dc:creator>
      <dc:date>2023-06-02T16:44:25Z</dc:date>
    </item>
    <item>
      <title>Re: Setup an alert but omit certain time of day</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-setup-an-alert-but-omit-certain-time-of-day/m-p/645588#M223522</link>
      <description>&lt;P&gt;FYI, solution found by a co-worker.&amp;nbsp; Here is the search that omits/filters 1am UTC from the results (a second before and after):&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;index=morpheus6* "Found ANC VITC in source 01:00:00;00" | where !((date_hour = 1 AND date_minute = 0 AND date_second = 0) OR (date_hour = 00 AND date_minute = 59 AND date_second = 59))&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2023 17:08:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-setup-an-alert-but-omit-certain-time-of-day/m-p/645588#M223522</guid>
      <dc:creator>ScottW1</dc:creator>
      <dc:date>2023-06-02T17:08:24Z</dc:date>
    </item>
  </channel>
</rss>

