Splunk ITSI

Splunk ITSI - How to Disable/enable Correlation searches during a particular time.

jk0061444
Explorer

Hi All

In our environment, servers are put under maintenance (serves are shutdown) at a particular time of a day . So we need to disable the Correlation searches during this period .To avoid Incidents getting created .

How can we disable/enable an Correlation searches  during a particular time. 

Please let me know if you have any suggestions 

 

Thanks and Regards

 

0 Karma

dlm
Path Finder

There is no way to automatically shut off the correlation searches based on time. It is a manual process. You can only put the services and entities into maintenance. 

https://docs.splunk.com/Documentation/ITSI/4.2.1/Configure/MaintenanceWindows

Even though this is an old post, I figured I would answer it because there are a lot of new people coming into the application.

 

Also, If this is something you feel needs to be a feature of the maintenance process, then put in an enhancement. It is voted on, so get all your friends and coworkers to vote. 

0 Karma
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...