Alerting
Highlighted

Splunk Alert for specific time period

Explorer

Hi, does anyone know how to create a realtime alert which should trigger the alert only from Thursday 6PM to Sunday 6AM and any other day between 6PM to 6 AM ?

the search query will be something similar to the below.

index=wineventlog sourcetype="WinEventLog:Security" EventCode=4625 user="Administrator"

I need to get an alert if this particular event occurs between Thursday 6PM to Sunday 6AM and any other day between 6PM to 6 AM.

Can this be done in a single alert or do we have to create multiple alerts with different cron schedules. ?

Looking forward to your suggestions.

Regards
Sajin

Highlighted

Re: Splunk Alert for specific time period

Motivator

You can only have 1 cron schedule per alert. So you will need multiple alerts.

0 Karma
Highlighted

Re: Splunk Alert for specific time period

Explorer

have configured multiple alerts currently and wanted to find if it is possible in a single alert.

0 Karma
Highlighted

Re: Splunk Alert for specific time period

Champion

At what frequency alert is running?

0 Karma
Highlighted

Re: Splunk Alert for specific time period

Explorer

should run in realtime. And only on weekends and non-working hours.

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.