Getting Data In

How to create custom relative date and time in Splunk



I have lot of alerts which even trigger during the maintenance period causing false incidents. The cmdb has the maintenance schedule but in the formats like "1st&3rd-Friday@10am", "2nd&4th-Monday@6pm" and so on. I am trying to prase this time in Splunk search query so that i can create Starttime & Endtime for which the alert will not trigger.

I am able to "| eval CurrentDay = strftime(now(), "%A")" which gives me the current day like whether today is Monday/Tuesday or what day, but how do i find out if it is first monday of the month or 2nd monday or so for me to address this requirement.

Anyone who can point me towards some direction in addressing this?

0 Karma