Alerting

Rest API

alvingeo
New Member

Hi Splunk Team,

I am looking for the API where  we can blackout monitoring on Azure VM while these VMs are under patching process. The patch will happen to a group of VMs together based on its tag in azure. Can you please suggest me an approach to group VM and then blackout monitoring alerts and then re-enable when the patching processing is completed?

 

Thanks in advance

George

Labels (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

I do nit understand what you want from splunk in here. Splunk as such "only" processes events. What are you monitoring your Azure with? How are you getting data into splunk? What do you have now and what is the expected result? Are you using ITSI?

0 Karma

alvingeo
New Member

Thank you for the response.  In Azure we have VMs which are integrated with splunk monitoring, that. will send alert notifications  based on VM's performance . We want to switch off  the alerts for example memory usage or restart while the VMs undergo patching. So looking for an API to tell splunk to blackout this monitoring during the patching window. do you have any APIs or documentations where we can find how to do this over a splunk api call. 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

It doesn't work like that. At least to some extent. I'm not sure what is the "delivery mode" of those alerts and other events but if I understand correctly, splunk is only a receiver of alerts generated by this azure monitoring functionality. So most probably even if you disabled the splunk input for some time, the events would get queued on the sending side and would get sent when you reenable the input. So you should rather disable the monitoring not on splunk's side but on the azure monitoring solution's side.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...