One of our users created a real-time search that triggers an alert every time, so there are thousands of alerts built up. Is it possible to bulk-delete them somehow? Where does the alert window pull those events from?
I saw this post:
http://splunk-base.splunk.com/answers/517/how-to-search-recent-alerts-fired-by-splunk
If I run those searches and pipe them to delete, will it clear up the alert window?
Thx.
Craig
Hi
Don't pipe to delete alert
just stop triggering by select throtting attribut and go to Activity > Triggered Alerts select all the alert that was triggered and delete them.
http://docs.splunk.com/Documentation/Splunk/6.2.2/Alert/Reviewtriggeredalerts
hi
I have bulk of triggered alert notifications. how can I delete at once.
Just disabling the alert will already remove the triggered alerts...
I am not sure how to do what you want - but DON'T pipe to delete!! You will be deleting Splunk internal log entries, and that's not a good thing.