Alerting

How can we suppress a set of alerts?

danielbb
Motivator

Sometimes, especially over the weekends we need to suppress a large set of alerts. Is there a way to do it in bulk? meaning, to suppress a set of alerts and after some time to bring them back.

Tags (2)
0 Karma

somesoni2
Revered Legend

If possible, organize them in a separate app (all the alerts that you want to disabled/enable). When the weekend comes, just disable the app, Enable the app on Monday.

danielbb
Motivator

Thank you @somesoni2 !

If they are already in separate apps, can we also have a savedsearches.conf at $SPLUNK_HOME/etc/system/local with the alerts stanzas with disabled = true. By activating this savedsearches.conf, we can disable all the alerts mentioned in this config file. Will it work?

0 Karma

arjunpkishore5
Motivator

You can edit the savedsearches.conf or use the REST API to programmatically disable the alerts - http://docs.splunk.com/Documentation/Splunk/8.0.2/RESTREF/RESTsearch#saved.2Fsearches

Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.