Splunk ITSI

Is it possible for Alerts blackout functionality in Splunk/ITSI?

mallempatisreed
Explorer

hi Team,

During any maintenance releases of WebSite , is it possible to have monitoring alerts blackout functionality in splunk so we don't receive any notable events/alerts in ITSI or Splunk.

Or is it possible to enable the blackout of a specific services in ITSI for not generating notable events.

Thanks,
Sreedhar

0 Karma

RickvdIJ
Explorer

In Splunk ITSI you have something like "Maintenance Schedule" where you set a timeperiod which will "blackout" specific entities or services. Check out this link for more information: https://docs.splunk.com/Documentation/ITSI/4.0.3/Configure/MaintenanceWindows

In Splunk itself you could create a macro or lookup functionality which checks if a maintenance release is active. Then the alert must be configured to check this result. Though it would be more work to set up at first, but when you release often it is quicker.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...