You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Splunk中实现每月首/末工作日的告警配置

实现Splunk中判断当月最后一个工作日的查询逻辑

核心查询代码

以下是直接生成is_last_business_day字段的Splunk查询,可直接嵌入到你的告警查询中:

| makeresults 
| eval current_date=strftime(_time, "%Y-%m-%d")
| eval month_end=strftime(relative_time(_time, "+1mon@mon-1d"), "%Y-%m-%d")
| eval days_until_end=days(month_end, current_date)
| eval is_weekend=if(match(strftime(_time, "%w"), "^(0|6)$"), 1, 0)
| eval is_last_business_day=0
| foreach [mvindex(mvrange(0, days_until_end+1), 0, days_until_end)] 
    [ eval check_date=strftime(relative_time(_time, "+<<FIELD>>d"), "%Y-%m-%d")
      eval check_weekend=if(match(strftime(relative_time(_time, "+<<FIELD>>d"), "%w"), "^(0|6)$"), 1, 0)
      eval is_last_business_day=if(days_until_end=0 AND is_weekend=0, 1, if(check_weekend=0 AND <<FIELD>>=days_until_end, 1, is_last_business_day)) ]
| fields current_date is_last_business_day

逻辑拆解

  • makeresults:生成一条基础事件作为计算载体
  • current_date:提取当前查询时间的标准日期格式
  • month_end:通过时间偏移计算当月最后一天的日期
  • days_until_end:计算当前日期到月末的天数差
  • is_weekend:标记当前日期是否为周末(周日=0,周六=6)
  • foreach循环:从当前日期遍历至月末,找到最后一个非周末日期,若当前日期匹配则将is_last_business_day设为1

结合告警场景的完整示例

将上述判断逻辑与你的文件交付检查查询整合,最终可直接用于告警:

# 替换为你的文件交付检查基础查询
index=your_index sourcetype=your_sourcetype 
| stats count as file_count 
# 插入最后一个工作日判断逻辑
| append [
    | makeresults 
    | eval current_date=strftime(_time, "%Y-%m-%d")
    | eval month_end=strftime(relative_time(_time, "+1mon@mon-1d"), "%Y-%m-%d")
    | eval days_until_end=days(month_end, current_date)
    | eval is_weekend=if(match(strftime(_time, "%w"), "^(0|6)$"), 1, 0)
    | eval is_last_business_day=0
    | foreach [mvindex(mvrange(0, days_until_end+1), 0, days_until_end)] 
        [ eval check_date=strftime(relative_time(_time, "+<<FIELD>>d"), "%Y-%m-%d")
          eval check_weekend=if(match(strftime(relative_time(_time, "+<<FIELD>>d"), "%w"), "^(0|6)$"), 1, 0)
          eval is_last_business_day=if(days_until_end=0 AND is_weekend=0, 1, if(check_weekend=0 AND <<FIELD>>=days_until_end, 1, is_last_business_day)) ]
    | fields is_last_business_day
]
| stats values(file_count) as file_count values(is_last_business_day) as is_last_business_day
# 匹配你需要的告警条件
| where file_count < 1 AND is_last_business_day=1

内容的提问来源于stack exchange,提问作者Fuat Ulugay

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.22 00:21:40