Delete undeliverable notifications in ArcSight Express
I have configured rule notification and selected
"acknowledge" checkbox on the rule action tab.
Initially customer received mail notification for
configured rules, now if I check the notification parameters under console,
there are many unacknowledged, undelivered notifications I am able to see.
Customer not receiving the mail notification, i want to
clear these cache notifications.
This is from an old ArcSight KB:
How to delete all the notifications and their statuses from the database all at the same time?
If certain notifications are no longer needed, have become obsolete, or the number of them has become so large that it affects performance, you may want to delete all notifications at once.
Note: The following steps will permanently and irrevocably remove all existing notifications and their statuses from the database.
1. Stop the Manager Service.
2. Backup the system tables
3. Login to the Database Server as the arcsight user
3. At the SQL> prompt, execute the following commands:
delete from arc_notification_history;
delete from arc_notification_registry;
This worked for me in AE 3.0 and 4.0.
1.- /etc/init.d/arcsight_services stop manager
2.- cd /opt/arcsight/logger/current/arcsight/bin/
3.- ./mysql -u arcsight -p
4.- mysql> use arcsight;
5.- mysql> delete from arc_notification_history;
6.- mysql> delete from arc_notification_registry;
7.- mysql> commit;
8.- /etc/init.d/arcsight_services start manager
A recommendation useful:
First identify the rule that is filling you with notifications and disable it.
Work Fine for:
So it should work for you too.