如何在Splunk中实现每月首/末工作日的告警配置
实现Splunk中判断当月最后一个工作日的查询逻辑
核心查询代码
以下是直接生成is_last_business_day字段的Splunk查询,可直接嵌入到你的告警查询中:
| makeresults | eval current_date=strftime(_time, "%Y-%m-%d") | eval month_end=strftime(relative_time(_time, "+1mon@mon-1d"), "%Y-%m-%d") | eval days_until_end=days(month_end, current_date) | eval is_weekend=if(match(strftime(_time, "%w"), "^(0|6)$"), 1, 0) | eval is_last_business_day=0 | foreach [mvindex(mvrange(0, days_until_end+1), 0, days_until_end)] [ eval check_date=strftime(relative_time(_time, "+<<FIELD>>d"), "%Y-%m-%d") eval check_weekend=if(match(strftime(relative_time(_time, "+<<FIELD>>d"), "%w"), "^(0|6)$"), 1, 0) eval is_last_business_day=if(days_until_end=0 AND is_weekend=0, 1, if(check_weekend=0 AND <<FIELD>>=days_until_end, 1, is_last_business_day)) ] | fields current_date is_last_business_day
逻辑拆解
makeresults:生成一条基础事件作为计算载体current_date:提取当前查询时间的标准日期格式month_end:通过时间偏移计算当月最后一天的日期days_until_end:计算当前日期到月末的天数差is_weekend:标记当前日期是否为周末(周日=0,周六=6)foreach循环:从当前日期遍历至月末,找到最后一个非周末日期,若当前日期匹配则将is_last_business_day设为1
结合告警场景的完整示例
将上述判断逻辑与你的文件交付检查查询整合,最终可直接用于告警:
# 替换为你的文件交付检查基础查询 index=your_index sourcetype=your_sourcetype | stats count as file_count # 插入最后一个工作日判断逻辑 | append [ | makeresults | eval current_date=strftime(_time, "%Y-%m-%d") | eval month_end=strftime(relative_time(_time, "+1mon@mon-1d"), "%Y-%m-%d") | eval days_until_end=days(month_end, current_date) | eval is_weekend=if(match(strftime(_time, "%w"), "^(0|6)$"), 1, 0) | eval is_last_business_day=0 | foreach [mvindex(mvrange(0, days_until_end+1), 0, days_until_end)] [ eval check_date=strftime(relative_time(_time, "+<<FIELD>>d"), "%Y-%m-%d") eval check_weekend=if(match(strftime(relative_time(_time, "+<<FIELD>>d"), "%w"), "^(0|6)$"), 1, 0) eval is_last_business_day=if(days_until_end=0 AND is_weekend=0, 1, if(check_weekend=0 AND <<FIELD>>=days_until_end, 1, is_last_business_day)) ] | fields is_last_business_day ] | stats values(file_count) as file_count values(is_last_business_day) as is_last_business_day # 匹配你需要的告警条件 | where file_count < 1 AND is_last_business_day=1
内容的提问来源于stack exchange,提问作者Fuat Ulugay
相关产品推荐
相关产品推荐

