Alerting

How to bulk delete alerts

responsys_cm
Builder

One of our users created a real-time search that triggers an alert every time, so there are thousands of alerts built up. Is it possible to bulk-delete them somehow? Where does the alert window pull those events from?

I saw this post:

http://splunk-base.splunk.com/answers/517/how-to-search-recent-alerts-fired-by-splunk

If I run those searches and pipe them to delete, will it clear up the alert window?

Thx.

Craig

Tags (1)

chimell
Motivator

Hi
Don't pipe to delete alert
just stop triggering by select throtting attribut and go to Activity > Triggered Alerts select all the alert that was triggered and delete them.
http://docs.splunk.com/Documentation/Splunk/6.2.2/Alert/Reviewtriggeredalerts

0 Karma

rashid47010
Communicator

hi
I have bulk of triggered alert notifications. how can I delete at once.

0 Karma

johndoeqisoa
Engager

Just disabling the alert will already remove the triggered alerts...

lguinn2
Legend

I am not sure how to do what you want - but DON'T pipe to delete!! You will be deleting Splunk internal log entries, and that's not a good thing.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...