Splunk ITSI

Splunk ITSI - How to Disable/enable Correlation searches during a particular time.

jk0061444
Explorer

Hi All

In our environment, servers are put under maintenance (serves are shutdown) at a particular time of a day . So we need to disable the Correlation searches during this period .To avoid Incidents getting created .

How can we disable/enable an Correlation searches  during a particular time. 

Please let me know if you have any suggestions 

 

Thanks and Regards

 

0 Karma

dlm
Path Finder

There is no way to automatically shut off the correlation searches based on time. It is a manual process. You can only put the services and entities into maintenance. 

https://docs.splunk.com/Documentation/ITSI/4.2.1/Configure/MaintenanceWindows

Even though this is an old post, I figured I would answer it because there are a lot of new people coming into the application.

 

Also, If this is something you feel needs to be a feature of the maintenance process, then put in an enhancement. It is voted on, so get all your friends and coworkers to vote. 

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...