Hello
I'm using Splunk Cloud and im looking for an option to disable multiple alert using rest api or script so it will be semi automatic
Since I'm using the Cloud, I don't have access to savedsearches.conf file.
Any ideas ?
Thanks
Hi @SplunkySplunk,
there isn't any option to do this except savedsearches.conf modify, but this action isn't possible on Splunk Cloud.
Action on multiple objects (like alerts) is an issue that Splunk has from its beginning. now there's a request in Splunk Ideas but it isn't still taken in consideration because there are too few votes: https://ideas.splunk.com/ideas/PLECID-I-645 .
Ciao.
Giuseppe