<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to snooze or temporarily disable scheduled searches? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-to-snooze-or-temporarily-disable-scheduled-searches/m-p/420457#M7335</link>
    <description>&lt;P&gt;You can create a one-time cron job to call the CLI to enable a particular search, or even directly modify the &lt;CODE&gt;savedsearches.conf&lt;/CODE&gt; file.&lt;/P&gt;</description>
    <pubDate>Sat, 20 Apr 2019 13:13:05 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2019-04-20T13:13:05Z</dc:date>
    <item>
      <title>How to snooze or temporarily disable scheduled searches?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-snooze-or-temporarily-disable-scheduled-searches/m-p/420455#M7333</link>
      <description>&lt;P&gt;Sometimes (like on holidays), I want to disable an alert for a period of time so that it doesn't fire and cause operators to panic. Usually, we do one of two things:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Manually disable the alert on the day we want it to stop running, then manually re-enable it as soon as we want it to run again. This often requires waiting until the end of the day before a holiday, then coming in as soon as possible the following work day and remembering to re-enable everything.&lt;/LI&gt;
&lt;LI&gt;Tweak the cron schedule so the search doesn't run on the days of the week the holidays fall on. This is less transparent and still requires someone to manually alter the alert's schedule.&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;I'm wondering if there's a better solution, maybe something like a snooze function where we can say ahead of time that we don't want the alert to run on days x, y, z, but then resume normal functionality. This would be more like a planned outage than reactive throttling. &lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2019 14:39:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-snooze-or-temporarily-disable-scheduled-searches/m-p/420455#M7333</guid>
      <dc:creator>mbavlsik</dc:creator>
      <dc:date>2019-04-19T14:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to snooze or temporarily disable scheduled searches?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-snooze-or-temporarily-disable-scheduled-searches/m-p/420456#M7334</link>
      <description>&lt;P&gt;Unfortunately there is no snooze facility. It has been a long running feature request.&lt;/P&gt;</description>
      <pubDate>Sat, 20 Apr 2019 06:55:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-snooze-or-temporarily-disable-scheduled-searches/m-p/420456#M7334</guid>
      <dc:creator>burwell</dc:creator>
      <dc:date>2019-04-20T06:55:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to snooze or temporarily disable scheduled searches?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-snooze-or-temporarily-disable-scheduled-searches/m-p/420457#M7335</link>
      <description>&lt;P&gt;You can create a one-time cron job to call the CLI to enable a particular search, or even directly modify the &lt;CODE&gt;savedsearches.conf&lt;/CODE&gt; file.&lt;/P&gt;</description>
      <pubDate>Sat, 20 Apr 2019 13:13:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-snooze-or-temporarily-disable-scheduled-searches/m-p/420457#M7335</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-04-20T13:13:05Z</dc:date>
    </item>
  </channel>
</rss>

