Alerting

Rest API

alvingeo
New Member

Hi Splunk Team,

I am looking for the API where  we can blackout monitoring on Azure VM while these VMs are under patching process. The patch will happen to a group of VMs together based on its tag in azure. Can you please suggest me an approach to group VM and then blackout monitoring alerts and then re-enable when the patching processing is completed?

 

Thanks in advance

George

Labels (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

I do nit understand what you want from splunk in here. Splunk as such "only" processes events. What are you monitoring your Azure with? How are you getting data into splunk? What do you have now and what is the expected result? Are you using ITSI?

0 Karma

alvingeo
New Member

Thank you for the response.  In Azure we have VMs which are integrated with splunk monitoring, that. will send alert notifications  based on VM's performance . We want to switch off  the alerts for example memory usage or restart while the VMs undergo patching. So looking for an API to tell splunk to blackout this monitoring during the patching window. do you have any APIs or documentations where we can find how to do this over a splunk api call. 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

It doesn't work like that. At least to some extent. I'm not sure what is the "delivery mode" of those alerts and other events but if I understand correctly, splunk is only a receiver of alerts generated by this azure monitoring functionality. So most probably even if you disabled the splunk input for some time, the events would get queued on the sending side and would get sent when you reenable the input. So you should rather disable the monitoring not on splunk's side but on the azure monitoring solution's side.

0 Karma
Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...