We regularly perform patching activity on Windows servers under monitoring in Splunk where we have to initiate maintenance window for 300 to 400 servers on one go. We dont want to put entire service into maintenance which will affect monitoring on other Windows servers.
We tried using REST API but it's not quite useful because start and end time in epoch, servers names cannot be used directly.
Please let me know whether we have any custom solution to achieve this requirement.