Splunk Search
Highlighted

Searching with some time slots excluded

Explorer

I have some saved searches which should not trigger during certain window.
For example, everyday from 12:00 AM to 2:00 AM none of the searches should trigger. In all other times, it should trigger as per the defined interval (10 minutes).

Please suggest how to achieve this?

Tags (2)
0 Karma
Highlighted

Re: Searching with some time slots excluded

Builder

You can add the following to the end of your searches

| where date_hour >2

or you can schedule the search to only run during the hours you are interested using cron. for example if you wanted a search to run every 5 minutes but not between 2 and 4 am.

*/5 0-1,4-23 * * * 

View solution in original post