Sometimes (like on holidays), I want to disable an alert for a period of time so that it doesn't fire and cause operators to panic. Usually, we do one of two things:
I'm wondering if there's a better solution, maybe something like a snooze function where we can say ahead of time that we don't want the alert to run on days x, y, z, but then resume normal functionality. This would be more like a planned outage than reactive throttling.
You can create a one-time cron job to call the CLI to enable a particular search, or even directly modify the savedsearches.conf
file.
Unfortunately there is no snooze facility. It has been a long running feature request.