Hi All,
I have created a custom alert in splunk and I want to put a suppression window in that alert on daily basis from 12am UTC -7am UTC. How can this be achieved? from cron expression or adding something to the original query?
Please help!!!
you need to schedule same search multiple times with different cron jobs
*/15 8-23 * * *
The above schedules job except below schedules
00:00,00:15........................,07:00,[07:15,07:30,07:45]
you need only three schedules from above the ones enclosed in []
another cron to schedule job to run at 07:15,07:30,07:45.
so you will need total 2 different cron schedules as below
*/15 8-23 * * *
15,30,45 7 * * *
what is the frequency of schedule and should 12 AM UTC - 7 AM UTC be excluded from schedule?
yes correct, frequency is 15 mins, monday to friday.