Hi, I have an alert which runs every 15 minutes as of now but what i want is to NOT trigger from 1:30 AM to 2:30 AM everyday. That's the time when my server cache gets flushed and the spike in the response time is usual. So I don't want to trigger the alert at this time.
Due to this we are getting false alarms.
How do i achieve this. My query is -
index=test sourcetype=access_combined_wcookie POST requested_content=/checkout/your-order*
| timechart span=15m avg(response_time_sec) as AvgResponseTime by host
| eval AvgResponseTime=round(AvgResponseTime,3)