Splunk Search

Suppression in Es by applying time limit

fahimeh
Explorer

Hello,

I want to write a suppression in Splunk ES that suppresses an event if a specific process occurs at 11 AM every day. This limitation should be applied to the raw logs because the ES rules execute within a specific time cycle and create notable events. My goal is to suppress the event when the rule runs, but only if the specific process exists at 11 AM.

How can I apply this time constraint in the suppression? Can I do this through the search I write? How?

How can I implement this time constraint on raw data? I need to limit the time in the raw event.

 

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @fahimeh ,

use the rule you need, e.g. if the haour cannot be 11 AM, you can insert in your search time_hour|=11.

It depends on your requirements.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @fahimeh ,

a suppression rule is a search that you can build as you need, containing also the time rules.

Ciao.

Giuseppe

0 Karma

fahimeh
Explorer
Thank you for your reply

Which time rules can I use in a search? Most time-related commands include | (like eval).

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @fahimeh ,

use the rule you need, e.g. if the haour cannot be 11 AM, you can insert in your search time_hour|=11.

It depends on your requirements.

Ciao.

Giuseppe

fahimeh
Explorer

thank you🌸
I will test and tell you exactly how it worked.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @fahimeh ,

good for you, see next time!

let me know if I can help you more, or, please, accept one answer for the other people of Community.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...