Splunk ITSI

Splunk ITSI - How to Disable/enable Correlation searches during a particular time.

jk0061444
Explorer

Hi All

In our environment, servers are put under maintenance (serves are shutdown) at a particular time of a day . So we need to disable the Correlation searches during this period .To avoid Incidents getting created .

How can we disable/enable an Correlation searches  during a particular time. 

Please let me know if you have any suggestions 

 

Thanks and Regards

 

0 Karma

dlm
Path Finder

There is no way to automatically shut off the correlation searches based on time. It is a manual process. You can only put the services and entities into maintenance. 

https://docs.splunk.com/Documentation/ITSI/4.2.1/Configure/MaintenanceWindows

Even though this is an old post, I figured I would answer it because there are a lot of new people coming into the application.

 

Also, If this is something you feel needs to be a feature of the maintenance process, then put in an enhancement. It is voted on, so get all your friends and coworkers to vote. 

0 Karma
Get Updates on the Splunk Community!

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...

Enterprise Security Content Update (ESCU) | New Releases

In April, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security ...