Alerting

Rest API

alvingeo
New Member

Hi Splunk Team,

I am looking for the API where  we can blackout monitoring on Azure VM while these VMs are under patching process. The patch will happen to a group of VMs together based on its tag in azure. Can you please suggest me an approach to group VM and then blackout monitoring alerts and then re-enable when the patching processing is completed?

 

Thanks in advance

George

Labels (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

I do nit understand what you want from splunk in here. Splunk as such "only" processes events. What are you monitoring your Azure with? How are you getting data into splunk? What do you have now and what is the expected result? Are you using ITSI?

0 Karma

alvingeo
New Member

Thank you for the response.  In Azure we have VMs which are integrated with splunk monitoring, that. will send alert notifications  based on VM's performance . We want to switch off  the alerts for example memory usage or restart while the VMs undergo patching. So looking for an API to tell splunk to blackout this monitoring during the patching window. do you have any APIs or documentations where we can find how to do this over a splunk api call. 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

It doesn't work like that. At least to some extent. I'm not sure what is the "delivery mode" of those alerts and other events but if I understand correctly, splunk is only a receiver of alerts generated by this azure monitoring functionality. So most probably even if you disabled the splunk input for some time, the events would get queued on the sending side and would get sent when you reenable the input. So you should rather disable the monitoring not on splunk's side but on the azure monitoring solution's side.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...