Alerting

How to bulk delete alerts

responsys_cm
Builder

One of our users created a real-time search that triggers an alert every time, so there are thousands of alerts built up. Is it possible to bulk-delete them somehow? Where does the alert window pull those events from?

I saw this post:

http://splunk-base.splunk.com/answers/517/how-to-search-recent-alerts-fired-by-splunk

If I run those searches and pipe them to delete, will it clear up the alert window?

Thx.

Craig

Tags (1)

chimell
Motivator

Hi
Don't pipe to delete alert
just stop triggering by select throtting attribut and go to Activity > Triggered Alerts select all the alert that was triggered and delete them.
http://docs.splunk.com/Documentation/Splunk/6.2.2/Alert/Reviewtriggeredalerts

0 Karma

rashid47010
Communicator

hi
I have bulk of triggered alert notifications. how can I delete at once.

0 Karma

johndoeqisoa
Engager

Just disabling the alert will already remove the triggered alerts...

lguinn2
Legend

I am not sure how to do what you want - but DON'T pipe to delete!! You will be deleting Splunk internal log entries, and that's not a good thing.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...