Alerting

How can we suppress a set of alerts?

danielbb
Motivator

Sometimes, especially over the weekends we need to suppress a large set of alerts. Is there a way to do it in bulk? meaning, to suppress a set of alerts and after some time to bring them back.

Tags (2)
0 Karma

somesoni2
Revered Legend

If possible, organize them in a separate app (all the alerts that you want to disabled/enable). When the weekend comes, just disable the app, Enable the app on Monday.

danielbb
Motivator

Thank you @somesoni2 !

If they are already in separate apps, can we also have a savedsearches.conf at $SPLUNK_HOME/etc/system/local with the alerts stanzas with disabled = true. By activating this savedsearches.conf, we can disable all the alerts mentioned in this config file. Will it work?

0 Karma

arjunpkishore5
Motivator

You can edit the savedsearches.conf or use the REST API to programmatically disable the alerts - http://docs.splunk.com/Documentation/Splunk/8.0.2/RESTREF/RESTsearch#saved.2Fsearches

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...