Alerting

How to bulk delete alerts

responsys_cm
Builder

One of our users created a real-time search that triggers an alert every time, so there are thousands of alerts built up. Is it possible to bulk-delete them somehow? Where does the alert window pull those events from?

I saw this post:

http://splunk-base.splunk.com/answers/517/how-to-search-recent-alerts-fired-by-splunk

If I run those searches and pipe them to delete, will it clear up the alert window?

Thx.

Craig

Tags (1)

chimell
Motivator

Hi
Don't pipe to delete alert
just stop triggering by select throtting attribut and go to Activity > Triggered Alerts select all the alert that was triggered and delete them.
http://docs.splunk.com/Documentation/Splunk/6.2.2/Alert/Reviewtriggeredalerts

0 Karma

rashid47010
Communicator

hi
I have bulk of triggered alert notifications. how can I delete at once.

0 Karma

johndoeqisoa
Engager

Just disabling the alert will already remove the triggered alerts...

lguinn2
Legend

I am not sure how to do what you want - but DON'T pipe to delete!! You will be deleting Splunk internal log entries, and that's not a good thing.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...