Alerting

How to bulk delete alerts

responsys_cm
Builder

One of our users created a real-time search that triggers an alert every time, so there are thousands of alerts built up. Is it possible to bulk-delete them somehow? Where does the alert window pull those events from?

I saw this post:

http://splunk-base.splunk.com/answers/517/how-to-search-recent-alerts-fired-by-splunk

If I run those searches and pipe them to delete, will it clear up the alert window?

Thx.

Craig

Tags (1)

chimell
Motivator

Hi
Don't pipe to delete alert
just stop triggering by select throtting attribut and go to Activity > Triggered Alerts select all the alert that was triggered and delete them.
http://docs.splunk.com/Documentation/Splunk/6.2.2/Alert/Reviewtriggeredalerts

0 Karma

rashid47010
Communicator

hi
I have bulk of triggered alert notifications. how can I delete at once.

0 Karma

johndoeqisoa
Engager

Just disabling the alert will already remove the triggered alerts...

lguinn2
Legend

I am not sure how to do what you want - but DON'T pipe to delete!! You will be deleting Splunk internal log entries, and that's not a good thing.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...