I've seen a few posts on the subject, but I'd like to know how we can disable the multiple alerts throughout the maintenance window.
For example, I'd like to disable alerts 1, 2, and 3 from Saturday 11:30 p.m. until Sunday 6:00 a.m.
Thank you in advance.
------------------------------------
reference alert query
index=ABC sourcetype=XYZ ("Internal System Error")
|stats count
|where count >=30
@gcusello
I'm a rookie, so I don't know much about creating lookup csv. If you could explain the detailed technique with steps, I'd appreciate it. 🙂
Hi @Rakzskull,
if you don't know how to create a lookup I hint to follow the Splunk Search Tutorial (https://docs.splunk.com/Documentation/Splunk/9.0.1/SearchTutorial/WelcometotheSearchTutorial)
Anyway, you have to:
Ciao.
Giuseppe
It could also be done via the REST API:
https://community.splunk.com/t5/Alerting/How-do-you-disable-enable-alerts-via-the-REST-API/m-p/44155...
There is also a good suggestion here to group the alerts by app, then disable the app:
https://community.splunk.com/t5/Alerting/How-can-we-suppress-a-set-of-alerts/m-p/480144
Need to add more points to this idea: +4 from me 😁
https://ideas.splunk.com/ideas/PLECID-I-297
Hi @Rakzskull,
if they are few, the easiest way it to manually disable them during maintenence period.
If you want to disable all the alert and you haven't scheduled reports or dashboards, you could disable the eMail configuration, so the alerts are triggered but the emails aren't sent.
There's a more elegant way, but it requires a little bit of work:
This surely is an interesting new feature, I hint to add it to Splunk Ideas.
Ciao.
Giuseppe