Other Usage

How to disable multiple alerts?

SplunkySplunk
Explorer

Hello

I'm using Splunk Cloud and im looking for an option to disable multiple alert using rest api or script so it will be semi automatic 

Since I'm using the Cloud, I don't have access to savedsearches.conf file.

Any ideas ?

Thanks

Labels (1)
Tags (4)

gcusello
SplunkTrust
SplunkTrust

Hi @SplunkySplunk,

there isn't any option to do this except savedsearches.conf modify, but this action isn't possible on Splunk Cloud.

Action on multiple objects (like alerts) is an issue that Splunk has from its beginning. now there's a request in Splunk Ideas but it isn't still taken in consideration because there are too few votes: https://ideas.splunk.com/ideas/PLECID-I-645

Ciao.

Giuseppe

 

0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...