Getting Data In

How to create custom relative date and time in Splunk

ashish9433
Communicator

Hi,

I have lot of alerts which even trigger during the maintenance period causing false incidents. The cmdb has the maintenance schedule but in the formats like "1st&3rd-Friday@10am", "2nd&4th-Monday@6pm" and so on. I am trying to prase this time in Splunk search query so that i can create Starttime & Endtime for which the alert will not trigger.

I am able to "| eval CurrentDay = strftime(now(), "%A")" which gives me the current day like whether today is Monday/Tuesday or what day, but how do i find out if it is first monday of the month or 2nd monday or so for me to address this requirement.

Anyone who can point me towards some direction in addressing this?

0 Karma
Get Updates on the Splunk Community!

Splunk App for Anomaly Detection End of Life Announcment

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...