alertmanager / alert_manager

Splunk Alert Manager with advanced reporting on alerts, workflows (modify assignee, status, severity) and auto-resolve features
Other
81 stars 44 forks source link

Support for bulk editing of alerts #191

Open michaelwilde opened 6 years ago

michaelwilde commented 6 years ago

it is desirable to be able to modify, tag, or resolve alerts in a bulk manner.

johnfromthefuture commented 6 years ago

Have you looked at the | modifyincidents command? I use that for doing mass updates of alerts and should be a viable workaround.

John Landers john@fromthefuture.net

On Wed, Jan 3, 2018 at 12:21 PM, michaelwilde notifications@github.com wrote:

it is desirable to be able to modify, tag, or resolve alerts in a bulk manner.

— You are receiving this because you are subscribed to this thread. Reply to this email directly, view it on GitHub https://github.com/simcen/alert_manager/issues/191, or mute the thread https://github.com/notifications/unsubscribe-auth/ASUiIubrG7NcJ9L5EH6HIDAu5hhEmfBwks5tG7cPgaJpZM4RSA-q .

Akes712 commented 6 years ago

Hi, I've been trying to close alerts in bulk as well. I have tried the |modifyincidents command, I'm able to resolve and assign owner in a bulk manner. However, my comments are not being reflected in the history table when we drilldown on searches.

bulk edit

johnfromthefuture commented 6 years ago

Can you search the alerts index and see if the comment is being recorded at all? If so, is the time stamping right?

Also, what version of AM are you running? I can look closer at this issue later...

On Wed, Jan 17, 2018 at 6:22 PM Akes712 notifications@github.com wrote:

Hi, I've been trying to close alerts in bulk as well. I have tried the |modifyincidents command, I'm able to resolve and assign owner in a bulk manner. However, my comments are not being reflected in the history table when we drilldown on searches.

[image: bulk edit] https://user-images.githubusercontent.com/35546251/35072606-48413d66-fc0b-11e7-9a2a-5fbe14e9f0ee.PNG

— You are receiving this because you commented.

Reply to this email directly, view it on GitHub https://github.com/simcen/alert_manager/issues/191#issuecomment-358483358, or mute the thread https://github.com/notifications/unsubscribe-auth/ASUiIsssznRPnwuHdxJ6dWimZty2rj1Eks5tLoC5gaJpZM4RSA-q .

-- -- Sent from a mobile device