Getting Data In

How to create custom relative date and time in Splunk

ashish9433
Communicator

Hi,

I have lot of alerts which even trigger during the maintenance period causing false incidents. The cmdb has the maintenance schedule but in the formats like "1st&3rd-Friday@10am", "2nd&4th-Monday@6pm" and so on. I am trying to prase this time in Splunk search query so that i can create Starttime & Endtime for which the alert will not trigger.

I am able to "| eval CurrentDay = strftime(now(), "%A")" which gives me the current day like whether today is Monday/Tuesday or what day, but how do i find out if it is first monday of the month or 2nd monday or so for me to address this requirement.

Anyone who can point me towards some direction in addressing this?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...