Splunk Enterprise Security

Is there a way to have a duration value account for weekends

Funderburg78
Path Finder

So in python coding you can use rrule to assign weekends in weeks and subtract them from your calculation.  I ask because I am getting a Ticket open dat, and a ticket close date and I am attempting to determine SLA values based on working days (i.e.; we are not open weekends and are only open 6am-6pm) for tickets that span nights or weekends, how can i remove those time values dynamically for data that is being automatically pulled from a ticket system and not using a static value like an excel spreadsheet.  i.e.; This needs to be able to continue updating as time goes....  Bonus points if you can help account for a 6am - 6pm workday for SLA timers... Bonus bonus if you know how to exclude holidays, LOL

Labels (1)
0 Karma

Funderburg78
Path Finder

I will try adapting this tomorrow and let you know if I have any issues 😛  Thanks so much for the reply.  If it works I will mark it as a solution as well.  In the meantime, Karma for the starting point 😛

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

I answered a similar question about a month ago.

https://community.splunk.com/t5/Splunk-Search/count-time-of-my-select-time-within-week-ends/m-p/5531...

The principle could be adapted to take account of time left in the day at the beginning and time used in the day at the end and multiplying the number of intervening work days by 12 hours and adding on the previously calculated partial days.

Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...