Splunk ITSI

Maintenance Window for bulk of servers under Splunk monitoring

EAR009
Explorer

We regularly perform patching activity on Windows servers under monitoring in Splunk where we have to initiate maintenance window for 300 to 400 servers on one go. We dont want to put entire service into maintenance which will affect monitoring on other Windows servers.

We tried using REST API but it's not quite useful because start and end time in epoch, servers names cannot be used directly.

Please let me know whether we have any custom solution to achieve this requirement.

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...