Splunk Search

Searching with some time slots excluded

anirbanukil
Explorer

I have some saved searches which should not trigger during certain window.
For example, everyday from 12:00 AM to 2:00 AM none of the searches should trigger. In all other times, it should trigger as per the defined interval (10 minutes).

Please suggest how to achieve this?

Tags (2)
0 Karma
1 Solution

BobM
Builder

You can add the following to the end of your searches

| where date_hour >2

or you can schedule the search to only run during the hours you are interested using cron. for example if you wanted a search to run every 5 minutes but not between 2 and 4 am.

*/5 0-1,4-23 * * * 

View solution in original post

BobM
Builder

You can add the following to the end of your searches

| where date_hour >2

or you can schedule the search to only run during the hours you are interested using cron. for example if you wanted a search to run every 5 minutes but not between 2 and 4 am.

*/5 0-1,4-23 * * * 

View solution in original post

Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!