{"id":4585,"date":"2019-09-24T17:35:40","date_gmt":"2019-09-24T15:35:40","guid":{"rendered":"http:\/\/contoso.se\/blog\/?p=4585"},"modified":"2019-09-24T17:35:41","modified_gmt":"2019-09-24T15:35:41","slug":"return-data-only-during-office-hours-and-workdays","status":"publish","type":"post","link":"http:\/\/contoso.se\/blog\/?p=4585","title":{"rendered":"Return data only during office hours and workdays"},"content":{"rendered":"\n<p>Today I want to share a log query that only returns logs generated between 09 and 18, during workdays. The example is working with security events, without any filters. To improve query performances it is strongly recommended to add more filters, for example, event ID or account.<br \/><br \/> 6.00:00:00 means Saturday and 7.00:00:00 means Sunday \ud83d\ude42 <\/p>\n\n\n\n<p>let startDateOfAlert = startofday(now());<br \/>\nlet StartAlertTime = startDateOfAlert + 9hours;<br \/>\nlet StopAlertTime = startDateOfAlert + 18hours;<br \/>\nSecurityEvent<br \/>\n| extend localTimestamp = TimeGenerated + 2h<br \/>\n| extend ByPassDays = dayofweek(localTimestamp)<br \/>\n| where ByPassDays &lt;&gt; &#8216;6.00:00:00&#8217;<br \/>\n| where ByPassDays &lt;&gt; &#8216;7.00:00:00&#8217;<br \/>\n| where localTimestamp &gt; StartAlertTime <br \/>\n| where localTimestamp &lt; StopAlertTime<br \/>\n| order by localTimestamp asc <\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Today I want to share a log query that only returns logs generated between 09 and 18, during workdays. The example is working with security events, without any filters. To improve query performances it is strongly recommended to add more filters, for example, event ID or account. 6.00:00:00 means Saturday and 7.00:00:00 means Sunday \ud83d\ude42 &hellip; <a href=\"http:\/\/contoso.se\/blog\/?p=4585\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0},"categories":[64,75,71],"tags":[72,74,76,73],"_links":{"self":[{"href":"http:\/\/contoso.se\/blog\/index.php?rest_route=\/wp\/v2\/posts\/4585"}],"collection":[{"href":"http:\/\/contoso.se\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/contoso.se\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/contoso.se\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/contoso.se\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4585"}],"version-history":[{"count":5,"href":"http:\/\/contoso.se\/blog\/index.php?rest_route=\/wp\/v2\/posts\/4585\/revisions"}],"predecessor-version":[{"id":4590,"href":"http:\/\/contoso.se\/blog\/index.php?rest_route=\/wp\/v2\/posts\/4585\/revisions\/4590"}],"wp:attachment":[{"href":"http:\/\/contoso.se\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4585"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/contoso.se\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4585"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/contoso.se\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4585"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}