Splunk Search

Disable the alerts while disable maintenance mode in master app?

Veeru
Path Finder

Hello Splunk team,

I am trying for a logic to disable the alerts in the particular app while I disable maintenance mode in master app
Is this possible in Splunk?

Please help me out with this?

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Veeru,

for my knowledge it isn't possible to disable all alert with one step, you have to disable all of them one by one.

As a workaround, if the main action of your alerts is sending an email, you could disable email sending for the maintenance period so alerts continue to fire but emails aren't generated.

In the same way, if the main action of your alerts is executing a script, e.g. to open a ticket on an external troubletickeing system, you could disable the script for the maintenance period.

Ciao.

Giuseppe

Veeru
Path Finder

Hello @gcusello 

Thank you for reply,

Can you please help me how to disable mails and tickets while i set to maintenance mode.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Veeru,

you can disable email sendings, simply temporary modifying the information about the email server at [Settings -- Server Settings -- eMail Setings], and then restore the correct information at the end of the maintenance period.

For the scripts, you have to intervene on the script, e.g. temporary renaming it.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...