Alerting

How to bulk delete alerts

responsys_cm
Builder

One of our users created a real-time search that triggers an alert every time, so there are thousands of alerts built up. Is it possible to bulk-delete them somehow? Where does the alert window pull those events from?

I saw this post:

http://splunk-base.splunk.com/answers/517/how-to-search-recent-alerts-fired-by-splunk

If I run those searches and pipe them to delete, will it clear up the alert window?

Thx.

Craig

Tags (1)

chimell
Motivator

Hi
Don't pipe to delete alert
just stop triggering by select throtting attribut and go to Activity > Triggered Alerts select all the alert that was triggered and delete them.
http://docs.splunk.com/Documentation/Splunk/6.2.2/Alert/Reviewtriggeredalerts

0 Karma

rashid47010
Communicator

hi
I have bulk of triggered alert notifications. how can I delete at once.

0 Karma

johndoeqisoa
Engager

Just disabling the alert will already remove the triggered alerts...

lguinn2
Legend

I am not sure how to do what you want - but DON'T pipe to delete!! You will be deleting Splunk internal log entries, and that's not a good thing.

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...