Splunk Search

Accounting for weekends and holidays

AlexeyPy
Engager

I'm trying to come up with a method of accounting for weekends and holidays. Tell me, how should I implement this algorithm?
Real case: we need to catch response on the application after 2 working days subject to weekends and holidays.

There is the idea to implement it with a lookup, however, will have to manually affix the holidays every year. I would like to automate this process completely.

Tags (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi AlexeyPy,
for week-ends you can add to your searches

date_wday="sunday" OR date_wday="saturday"

instead to manage holydays the only way is to create a lookup containing holyday dates and use it to filter your searches.

your_search (date_wday="sunday" OR date_wday="saturday" OR [ | inputlookup holydays.csv | fields date ] )

putting attention on the date format that must be the same for _time and your lookup.

Bye.
Giuseppe

Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...