Knowledge Management

How to use TA-webtools to disable multiple alerts/reports?

ips_mandar
Builder

HI,

I want to disable multiple alerts/reports using curl (TA-webtools)..so basically my results look like below-

title app id
report1  app1 https://abc.com:8089/servicesNS/nobody/app1/saved/searches/report1
report2  app2 https://abc.com:8089/servicesNS/nobody/app2/saved/searches/report2
report3  app3 https://abc.com:8089/servicesNS/nobody/app3/saved/searches/report3

 

How I can disable all id alert/reports in single query?

any help is appreciated!

@jkat54 

Labels (1)
Tags (1)
0 Karma
1 Solution

ips_mandar
Builder

Below is the spl how I achieved it-

...| eval url_string= id."/disable"
|map search="| curl uri=$url_string$ method=POST splunkauth=true"

View solution in original post

0 Karma

ips_mandar
Builder

Below is the spl how I achieved it-

...| eval url_string= id."/disable"
|map search="| curl uri=$url_string$ method=POST splunkauth=true"
0 Karma

ips_mandar
Builder

Thanks @jkat54 I was able to do using map command

0 Karma

jkat54
SplunkTrust
SplunkTrust

You could do this using the urifield option and eval.  Here's an example below:

 

no reason you can't do something like

| makeresults count=3
| streamstats count 

| eval uri="https://abc.com:8089/app".count."/report".count"

 

 

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...