Alerting

Rest API

alvingeo
New Member

Hi Splunk Team,

I am looking for the API where  we can blackout monitoring on Azure VM while these VMs are under patching process. The patch will happen to a group of VMs together based on its tag in azure. Can you please suggest me an approach to group VM and then blackout monitoring alerts and then re-enable when the patching processing is completed?

 

Thanks in advance

George

Labels (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

I do nit understand what you want from splunk in here. Splunk as such "only" processes events. What are you monitoring your Azure with? How are you getting data into splunk? What do you have now and what is the expected result? Are you using ITSI?

0 Karma

alvingeo
New Member

Thank you for the response.  In Azure we have VMs which are integrated with splunk monitoring, that. will send alert notifications  based on VM's performance . We want to switch off  the alerts for example memory usage or restart while the VMs undergo patching. So looking for an API to tell splunk to blackout this monitoring during the patching window. do you have any APIs or documentations where we can find how to do this over a splunk api call. 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

It doesn't work like that. At least to some extent. I'm not sure what is the "delivery mode" of those alerts and other events but if I understand correctly, splunk is only a receiver of alerts generated by this azure monitoring functionality. So most probably even if you disabled the splunk input for some time, the events would get queued on the sending side and would get sent when you reenable the input. So you should rather disable the monitoring not on splunk's side but on the azure monitoring solution's side.

0 Karma
Get Updates on the Splunk Community!

Splunk Platform | Upgrading your Splunk Deployment to Python 3.9

Splunk initially announced the removal of Python 2 during the release of Splunk Enterprise 8.0.0, aiming to ...

From Product Design to User Insights: Boosting App Developer Identity on Splunkbase

co-authored by Yiyun Zhu & Dan Hosaka Engaging with the Community at .conf24 At .conf24, we revitalized the ...

Detect and Resolve Issues in a Kubernetes Environment

We’ve gone through common problems one can encounter in a Kubernetes environment, their impacts, and the ...