All Apps and Add-ons

Alert Manager: How to suppress follow on alerts

afx
Contributor

Hi,

looks like I am missing something.

I have a Splunk alert that is a bit spammy. I would like to use the Alert Manager app to give me one alert a day, basically the first time this alert shows up. And be quiet for the rest of the day, just increase the duplicate counter.  

I can get alerts to be counted as duplicates, but I still get e-mails for all of them.

I have not found a way in the suppression rules to hide follow on alerts.

thx

afx

Labels (2)
1 Solution

my2ndhead
SplunkTrust
SplunkTrust

Currently there's no way to suppress emails from follow on alerts. I will take this as a feature request.

View solution in original post

0 Karma

my2ndhead
SplunkTrust
SplunkTrust

Currently there's no way to suppress emails from follow on alerts. I will take this as a feature request.

0 Karma

afx
Contributor

Absolutely yes please.

So far I have only been toying with Alert manager.

That feature would make it production worthy 😉

thx
afx

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...