Hello,
How would I specify the time frame in a search to provide me the events between 7am - 5pm weekdays and all results for weekends within the same search
Hi @troy44112,
in addition to the solution of @richgalloway, that completely answers to your question, you could also manage the holidays following the instruction that you can find in this my old answer: https://community.splunk.com/t5/Splunk-Search/Bank-holiday-exclusion-from-search-query/m-p/491071
Ciao.
Giuseppe
Here's one way if your data includes the date_* fields (usually true).
index=foo <<more search terms>>
| where ((date_wday="saturday" OR date_wday="sunday") OR (date_hour>=7 date_hour<17))