Alerting

How can we suppress a set of alerts?

danielbb
Motivator

Sometimes, especially over the weekends we need to suppress a large set of alerts. Is there a way to do it in bulk? meaning, to suppress a set of alerts and after some time to bring them back.

Tags (2)
0 Karma

somesoni2
Revered Legend

If possible, organize them in a separate app (all the alerts that you want to disabled/enable). When the weekend comes, just disable the app, Enable the app on Monday.

danielbb
Motivator

Thank you @somesoni2 !

If they are already in separate apps, can we also have a savedsearches.conf at $SPLUNK_HOME/etc/system/local with the alerts stanzas with disabled = true. By activating this savedsearches.conf, we can disable all the alerts mentioned in this config file. Will it work?

0 Karma

arjunpkishore5
Motivator

You can edit the savedsearches.conf or use the REST API to programmatically disable the alerts - http://docs.splunk.com/Documentation/Splunk/8.0.2/RESTREF/RESTsearch#saved.2Fsearches

Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...