Splunk Search

Disable the alerts while disable maintenance mode in master app?

Veeru
Path Finder

Hello Splunk team,

I am trying for a logic to disable the alerts in the particular app while I disable maintenance mode in master app
Is this possible in Splunk?

Please help me out with this?

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Veeru,

for my knowledge it isn't possible to disable all alert with one step, you have to disable all of them one by one.

As a workaround, if the main action of your alerts is sending an email, you could disable email sending for the maintenance period so alerts continue to fire but emails aren't generated.

In the same way, if the main action of your alerts is executing a script, e.g. to open a ticket on an external troubletickeing system, you could disable the script for the maintenance period.

Ciao.

Giuseppe

Veeru
Path Finder

Hello @gcusello 

Thank you for reply,

Can you please help me how to disable mails and tickets while i set to maintenance mode.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Veeru,

you can disable email sendings, simply temporary modifying the information about the email server at [Settings -- Server Settings -- eMail Setings], and then restore the correct information at the end of the maintenance period.

For the scripts, you have to intervene on the script, e.g. temporary renaming it.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...