Alerting

How to snooze or temporarily disable scheduled searches?

mbavlsik
Engager

Sometimes (like on holidays), I want to disable an alert for a period of time so that it doesn't fire and cause operators to panic. Usually, we do one of two things:

  1. Manually disable the alert on the day we want it to stop running, then manually re-enable it as soon as we want it to run again. This often requires waiting until the end of the day before a holiday, then coming in as soon as possible the following work day and remembering to re-enable everything.
  2. Tweak the cron schedule so the search doesn't run on the days of the week the holidays fall on. This is less transparent and still requires someone to manually alter the alert's schedule.

I'm wondering if there's a better solution, maybe something like a snooze function where we can say ahead of time that we don't want the alert to run on days x, y, z, but then resume normal functionality. This would be more like a planned outage than reactive throttling.

0 Karma

woodcock
Esteemed Legend

You can create a one-time cron job to call the CLI to enable a particular search, or even directly modify the savedsearches.conf file.

burwell
SplunkTrust
SplunkTrust

Unfortunately there is no snooze facility. It has been a long running feature request.

Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...