Alerting

Splunk Alert for specific time period

kpsajin
Explorer

Hi, does anyone know how to create a realtime alert which should trigger the alert only from Thursday 6PM to Sunday 6AM and any other day between 6PM to 6 AM ?

the search query will be something similar to the below.

index=wineventlog sourcetype="WinEventLog:Security" EventCode=4625 user="Administrator"

I need to get an alert if this particular event occurs between Thursday 6PM to Sunday 6AM and any other day between 6PM to 6 AM.

Can this be done in a single alert or do we have to create multiple alerts with different cron schedules. ?

Looking forward to your suggestions.

Regards
Sajin

p_gurav
Champion

At what frequency alert is running?

0 Karma

kpsajin
Explorer

should run in realtime. And only on weekends and non-working hours.

0 Karma

kmaron
Motivator

You can only have 1 cron schedule per alert. So you will need multiple alerts.

0 Karma

kpsajin
Explorer

have configured multiple alerts currently and wanted to find if it is possible in a single alert.

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...