Searches for "After-Hours" Activity
Using Sumo Logic for Security Monitoring use-cases, we like to monitor for activities that occur "after-hours". How would we structure a query that looks for events between say, 8PM - 5AM? We know how to build the query for the activities, but we're having issues figuring out how to specify the time window.
-
one way you could do this is use a cron schedule in the scheduled for the alert so it only runs at specific time windows each day. https://help.sumologic.com/03Send-Data/Sources/01Sources-for-Installed-Collectors/Script-Source/Cron-Examples-and-Reference
Please sign in to leave a comment.
Comments
2 comments