Splunk Search

Disable the alerts while disable maintenance mode in master app?

Veeru
Path Finder

Hello Splunk team,

I am trying for a logic to disable the alerts in the particular app while I disable maintenance mode in master app
Is this possible in Splunk?

Please help me out with this?

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Veeru,

for my knowledge it isn't possible to disable all alert with one step, you have to disable all of them one by one.

As a workaround, if the main action of your alerts is sending an email, you could disable email sending for the maintenance period so alerts continue to fire but emails aren't generated.

In the same way, if the main action of your alerts is executing a script, e.g. to open a ticket on an external troubletickeing system, you could disable the script for the maintenance period.

Ciao.

Giuseppe

Veeru
Path Finder

Hello @gcusello 

Thank you for reply,

Can you please help me how to disable mails and tickets while i set to maintenance mode.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Veeru,

you can disable email sendings, simply temporary modifying the information about the email server at [Settings -- Server Settings -- eMail Setings], and then restore the correct information at the end of the maintenance period.

For the scripts, you have to intervene on the script, e.g. temporary renaming it.

Ciao.

Giuseppe

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...