Splunk IT Service Intelligence

Splunk ITSI - How to Disable/enable Correlation searches during a particular time.


Hi All

In our environment, servers are put under maintenance (serves are shutdown) at a particular time of a day . So we need to disable the Correlation searches during this period .To avoid Incidents getting created .

How can we disable/enable an Correlation searches  during a particular time. 

Please let me know if you have any suggestions 


Thanks and Regards


0 Karma

New Member

There is no way to automatically shut off the correlation searches based on time. It is a manual process. You can only put the services and entities into maintenance. 


Even though this is an old post, I figured I would answer it because there are a lot of new people coming into the application.


Also, If this is something you feel needs to be a feature of the maintenance process, then put in an enhancement. It is voted on, so get all your friends and coworkers to vote. 

0 Karma
Get Updates on the Splunk Community!

BSides Splunk 2022 - The Call for Papers is now Open!

TLDR; Main Site: https://bsidessplunk.com CFP Site: https://bsidessplunk.com/cfp CFP Opens: December 15th, ...

Sending Metrics to Splunk Enterprise With the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

What's New in Splunk Cloud Platform 9.0.2208?!

Howdy!  We are happy to share the newest updates in Splunk Cloud Platform 9.0.2208! Analysts can benefit ...