Alerting

How to snooze or temporarily disable scheduled searches?

mbavlsik
Engager

Sometimes (like on holidays), I want to disable an alert for a period of time so that it doesn't fire and cause operators to panic. Usually, we do one of two things:

  1. Manually disable the alert on the day we want it to stop running, then manually re-enable it as soon as we want it to run again. This often requires waiting until the end of the day before a holiday, then coming in as soon as possible the following work day and remembering to re-enable everything.
  2. Tweak the cron schedule so the search doesn't run on the days of the week the holidays fall on. This is less transparent and still requires someone to manually alter the alert's schedule.

I'm wondering if there's a better solution, maybe something like a snooze function where we can say ahead of time that we don't want the alert to run on days x, y, z, but then resume normal functionality. This would be more like a planned outage than reactive throttling.

0 Karma

woodcock
Esteemed Legend

You can create a one-time cron job to call the CLI to enable a particular search, or even directly modify the savedsearches.conf file.

burwell
SplunkTrust
SplunkTrust

Unfortunately there is no snooze facility. It has been a long running feature request.

Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...