Hello experts,
Is there any easy way to use Splunk (maybe using look ups or a pre-defined function)to identify if a given event date is a holiday or just a weekend?
Thanks-
Wellington
Have you tried formatting your date/time to show day of the week? example would be eval dow=strftime(_time, "%a"), this will show Sun for sunday, etc. As for holidays, you can use a lookup table (http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Lookup)