Alerting

Rest API

alvingeo
New Member

Hi Splunk Team,

I am looking for the API where  we can blackout monitoring on Azure VM while these VMs are under patching process. The patch will happen to a group of VMs together based on its tag in azure. Can you please suggest me an approach to group VM and then blackout monitoring alerts and then re-enable when the patching processing is completed?

 

Thanks in advance

George

Labels (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

I do nit understand what you want from splunk in here. Splunk as such "only" processes events. What are you monitoring your Azure with? How are you getting data into splunk? What do you have now and what is the expected result? Are you using ITSI?

0 Karma

alvingeo
New Member

Thank you for the response.  In Azure we have VMs which are integrated with splunk monitoring, that. will send alert notifications  based on VM's performance . We want to switch off  the alerts for example memory usage or restart while the VMs undergo patching. So looking for an API to tell splunk to blackout this monitoring during the patching window. do you have any APIs or documentations where we can find how to do this over a splunk api call. 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

It doesn't work like that. At least to some extent. I'm not sure what is the "delivery mode" of those alerts and other events but if I understand correctly, splunk is only a receiver of alerts generated by this azure monitoring functionality. So most probably even if you disabled the splunk input for some time, the events would get queued on the sending side and would get sent when you reenable the input. So you should rather disable the monitoring not on splunk's side but on the azure monitoring solution's side.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...