Splunk Search

Disable the alerts while disable maintenance mode in master app?

Veeru
Path Finder

Hello Splunk team,

I am trying for a logic to disable the alerts in the particular app while I disable maintenance mode in master app
Is this possible in Splunk?

Please help me out with this?

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Veeru,

for my knowledge it isn't possible to disable all alert with one step, you have to disable all of them one by one.

As a workaround, if the main action of your alerts is sending an email, you could disable email sending for the maintenance period so alerts continue to fire but emails aren't generated.

In the same way, if the main action of your alerts is executing a script, e.g. to open a ticket on an external troubletickeing system, you could disable the script for the maintenance period.

Ciao.

Giuseppe

Veeru
Path Finder

Hello @gcusello 

Thank you for reply,

Can you please help me how to disable mails and tickets while i set to maintenance mode.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Veeru,

you can disable email sendings, simply temporary modifying the information about the email server at [Settings -- Server Settings -- eMail Setings], and then restore the correct information at the end of the maintenance period.

For the scripts, you have to intervene on the script, e.g. temporary renaming it.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...