Getting Data In

How to create custom relative date and time in Splunk

ashish9433
Communicator

Hi,

I have lot of alerts which even trigger during the maintenance period causing false incidents. The cmdb has the maintenance schedule but in the formats like "1st&3rd-Friday@10am", "2nd&4th-Monday@6pm" and so on. I am trying to prase this time in Splunk search query so that i can create Starttime & Endtime for which the alert will not trigger.

I am able to "| eval CurrentDay = strftime(now(), "%A")" which gives me the current day like whether today is Monday/Tuesday or what day, but how do i find out if it is first monday of the month or 2nd monday or so for me to address this requirement.

Anyone who can point me towards some direction in addressing this?

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...