<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Scheduled Search Alert Suppression during Maintenance Window in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Scheduled-Search-Alert-Suppression-during-Maintenance-Window/m-p/58031#M1242</link>
    <description>&lt;P&gt;Yeah, I don't think this would be too difficult.  My thought is:&lt;/P&gt;

&lt;P&gt;For all searches you do not want to send alerts during a given time period (maintenance, I assume), instead of having them send out email, have them run a script.  That script could say check for the existence of a file in a given location.  If that file exists, suppress email alerts.  If that file does not exist, send email as normal.&lt;/P&gt;</description>
    <pubDate>Sat, 12 Mar 2011 02:58:22 GMT</pubDate>
    <dc:creator>netwrkr</dc:creator>
    <dc:date>2011-03-12T02:58:22Z</dc:date>
    <item>
      <title>Scheduled Search Alert Suppression during Maintenance Window</title>
      <link>https://community.splunk.com/t5/Reporting/Scheduled-Search-Alert-Suppression-during-Maintenance-Window/m-p/58030#M1241</link>
      <description>&lt;P&gt;Hello,   Is there a way to categorize or group Searches to suppress email alerts during a scheduled time period without having to go to each Search?&lt;/P&gt;</description>
      <pubDate>Sat, 12 Mar 2011 02:00:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Scheduled-Search-Alert-Suppression-during-Maintenance-Window/m-p/58030#M1241</guid>
      <dc:creator>dlazo</dc:creator>
      <dc:date>2011-03-12T02:00:13Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled Search Alert Suppression during Maintenance Window</title>
      <link>https://community.splunk.com/t5/Reporting/Scheduled-Search-Alert-Suppression-during-Maintenance-Window/m-p/58031#M1242</link>
      <description>&lt;P&gt;Yeah, I don't think this would be too difficult.  My thought is:&lt;/P&gt;

&lt;P&gt;For all searches you do not want to send alerts during a given time period (maintenance, I assume), instead of having them send out email, have them run a script.  That script could say check for the existence of a file in a given location.  If that file exists, suppress email alerts.  If that file does not exist, send email as normal.&lt;/P&gt;</description>
      <pubDate>Sat, 12 Mar 2011 02:58:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Scheduled-Search-Alert-Suppression-during-Maintenance-Window/m-p/58031#M1242</guid>
      <dc:creator>netwrkr</dc:creator>
      <dc:date>2011-03-12T02:58:22Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled Search Alert Suppression during Maintenance Window</title>
      <link>https://community.splunk.com/t5/Reporting/Scheduled-Search-Alert-Suppression-during-Maintenance-Window/m-p/58032#M1243</link>
      <description>&lt;P&gt;I think I follow but that means we would have to change each alert - During to change it and make it run script instead, correct?&lt;/P&gt;</description>
      <pubDate>Sat, 12 Mar 2011 03:37:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Scheduled-Search-Alert-Suppression-during-Maintenance-Window/m-p/58032#M1243</guid>
      <dc:creator>dlazo</dc:creator>
      <dc:date>2011-03-12T03:37:10Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled Search Alert Suppression during Maintenance Window</title>
      <link>https://community.splunk.com/t5/Reporting/Scheduled-Search-Alert-Suppression-during-Maintenance-Window/m-p/58033#M1244</link>
      <description>&lt;P&gt;If I understand your question correctly - yes, you would have to make a one time change to any 'searches' that you don't want alerting during your maintenance window to filter first through a script.  Instead of those searches/alerts going directly to email, tell them to use the script which we discussed above.  HTH.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Mar 2011 01:38:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Scheduled-Search-Alert-Suppression-during-Maintenance-Window/m-p/58033#M1244</guid>
      <dc:creator>netwrkr</dc:creator>
      <dc:date>2011-03-15T01:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled Search Alert Suppression during Maintenance Window</title>
      <link>https://community.splunk.com/t5/Reporting/Scheduled-Search-Alert-Suppression-during-Maintenance-Window/m-p/58034#M1245</link>
      <description>&lt;P&gt;You could also use the custom condition alert search and have that look at your maintenance window to control supression.  This assumes you can express the window in terms of a splunk search.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2011 16:03:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Scheduled-Search-Alert-Suppression-during-Maintenance-Window/m-p/58034#M1245</guid>
      <dc:creator>jrodman</dc:creator>
      <dc:date>2011-03-18T16:03:58Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled Search Alert Suppression during Maintenance Window</title>
      <link>https://community.splunk.com/t5/Reporting/Scheduled-Search-Alert-Suppression-during-Maintenance-Window/m-p/58035#M1246</link>
      <description>&lt;P&gt;The simplest out of the box way I can think of to achieve this is to group all alerts for a set of hosts, environment, or application into a single Splunk app space. This app space wouldn't have anything but the alerts defined. You would simply disable/enable that app in Splunk to turn off/on all associated alerts.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2016 19:19:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Scheduled-Search-Alert-Suppression-during-Maintenance-Window/m-p/58035#M1246</guid>
      <dc:creator>bandit</dc:creator>
      <dc:date>2016-12-08T19:19:38Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled Search Alert Suppression during Maintenance Window</title>
      <link>https://community.splunk.com/t5/Reporting/Scheduled-Search-Alert-Suppression-during-Maintenance-Window/m-p/58036#M1247</link>
      <description>&lt;P&gt;Splunk Cloud does not allow us to Enable/Disable an application without a support ticket.  Our use case does not have a predefined window, but needs a control by a user.&lt;/P&gt;

&lt;P&gt;We can accomplish this using a search Macro.  &lt;/P&gt;

&lt;P&gt;1) Include your macro at the end of each related search.  Ex:  "&lt;CODE&gt;should_run&lt;/CODE&gt;"&lt;BR /&gt;
2) To enable the search define the macro to be:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;| noop&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;3) To disable the search define the macro to be something like: &lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;some_really_invalid_key="this will never be found"&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:51:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Scheduled-Search-Alert-Suppression-during-Maintenance-Window/m-p/58036#M1247</guid>
      <dc:creator>markbarber21</dc:creator>
      <dc:date>2020-09-29T16:51:02Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled Search Alert Suppression during Maintenance Window</title>
      <link>https://community.splunk.com/t5/Reporting/Scheduled-Search-Alert-Suppression-during-Maintenance-Window/m-p/58037#M1248</link>
      <description>&lt;P&gt;My solution, which works for environments up to medium size, is to create multple alerts,for example&lt;BR /&gt;
switch alerts - all&lt;BR /&gt;
switch alerts - ignore esxi ports&lt;BR /&gt;
swtich alerts - ignore firewall ports&lt;BR /&gt;
switch alerts - ignore hsm ports&lt;/P&gt;

&lt;P&gt;Normally, 'switch alerts - all' is enabled, but when maintenance is going occur on esxi hosts, we disabled 'switch alerts - all' and enable 'switch alerts - ignore esxi ports'.&lt;/P&gt;

&lt;P&gt;This allows a bit of control without writing a script to query your ticket tracking system, and using that data to query your cabling database, and then using that data to update a generic 'link state' alert because in my opinion, telling a NOC to ignore alerts is the worst thing you can do.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2018 16:50:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Scheduled-Search-Alert-Suppression-during-Maintenance-Window/m-p/58037#M1248</guid>
      <dc:creator>tvaniderstine</dc:creator>
      <dc:date>2018-10-15T16:50:27Z</dc:date>
    </item>
  </channel>
</rss>

