Getting Data In

How to create custom relative date and time in Splunk

ashish9433
Communicator

Hi,

I have lot of alerts which even trigger during the maintenance period causing false incidents. The cmdb has the maintenance schedule but in the formats like "1st&3rd-Friday@10am", "2nd&4th-Monday@6pm" and so on. I am trying to prase this time in Splunk search query so that i can create Starttime & Endtime for which the alert will not trigger.

I am able to "| eval CurrentDay = strftime(now(), "%A")" which gives me the current day like whether today is Monday/Tuesday or what day, but how do i find out if it is first monday of the month or 2nd monday or so for me to address this requirement.

Anyone who can point me towards some direction in addressing this?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...