Splunk ITSI

Splunk ITSI - How to Disable/enable Correlation searches during a particular time.

jk0061444
Explorer

Hi All

In our environment, servers are put under maintenance (serves are shutdown) at a particular time of a day . So we need to disable the Correlation searches during this period .To avoid Incidents getting created .

How can we disable/enable an Correlation searches  during a particular time. 

Please let me know if you have any suggestions 

 

Thanks and Regards

 

0 Karma

dlm
Path Finder

There is no way to automatically shut off the correlation searches based on time. It is a manual process. You can only put the services and entities into maintenance. 

https://docs.splunk.com/Documentation/ITSI/4.2.1/Configure/MaintenanceWindows

Even though this is an old post, I figured I would answer it because there are a lot of new people coming into the application.

 

Also, If this is something you feel needs to be a feature of the maintenance process, then put in an enhancement. It is voted on, so get all your friends and coworkers to vote. 

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...