Optimize detectors
Detector Optimization reviews existing detectors and identifies opportunities to improve monitoring quality.
Detector optimization is a built-in Splunk Observability Cloud experience that reviews existing detectors and identifies opportunities to improve monitoring quality.
Managing large numbers of detectors without clear guidance on which ones need attention can result in:
-
Alert fatigue caused by noisy or flapping detectors.
-
Important alerts not reaching a notification recipient.
-
Detectors monitoring inactive or outdated data.
-
Long-term muted or unused detectors remaining in the environment.
-
Excessive reliance on monitoring experts to identify configuration issues.
-
Reduced trust in alerts and slower incident response.
Detector optimization provides a prioritized, guided way to improve detector quality and reduce unnecessary alert noise. It helps you:
-
find detectors that generate excessive or low-value alerts.
-
identify stale, inactive, muted, or incompletely configured detectors.
-
understand why a detector was flagged.
-
review the expected impact of a recommended change.
-
apply supported fixes or dismiss recommendations.
-
review recently applied optimizations.
View the detectors that can be optimized
Use Detector optimization to view detectors that have optimization recommendations.
- Open Splunk Observability Cloud.
- Go to .
- On the Detectors page, select the Detector optimization tab.
Detector optimization details
Reference information about detector issues, filters, optimization recommendations, and available actions.
The Detector optimization page helps you find detectors and alert rules that need configuration cleanup or alert-noise reduction.
Summary card details
The summary cards provide a quick count of the most important detector issues found during the latest optimization scan:
|
Summary card |
What the card represents |
Why it matters |
|---|---|---|
|
Detector with no duration |
Displays the number of detectors that do not define a sustained duration, such as |
Without a duration, a detector can fire on short-lived metric spikes or temporary data changes. This can create noisy alerts that do not represent a sustained problem. |
|
Detector with same fire/clear threshold |
Displays the number of detectors where the fire threshold and clear threshold are the same, or where no separate clear threshold is configured. |
When the monitored value hovers around a single threshold, the alert can repeatedly fire and clear. This flapping behavior makes incidents harder to trust and increases alert noise. |
|
Detector with alert severity misalignment |
Displays the number of detectors whose severity distribution appears misaligned with actual alert behavior, for example too many Critical or Major alerts, severity inflation, or thresholds that keep alerts in a non-normal state too often. |
Misaligned severity can cause teams to treat low-priority symptoms as urgent incidents or miss the intended escalation path. It can also reduce trust in Critical and Major alerts. |
|
Detectors muted for 30d+ |
Displays the number of detectors that have been muted for at least 30 days, or whose alerts have been fully suppressed over the long-term muted lookback period. |
Long-term muted detectors usually indicate alert rules that are no longer useful, are too noisy, or have been intentionally suppressed instead of fixed. Keeping them muted can hide monitoring gaps and add stale configuration clutter. |
|
Detectors with no data for 7d+ |
Displays the number of detectors whose monitored metric or signal has had no active data for at least 7 days. These detectors might also have no recent alert activity because the underlying data is no longer being reported. |
A detector with no incoming data cannot alert meaningfully. It can create a false sense of coverage, especially when the metric, service, host, or dimension it monitors has been removed, renamed, or stopped reporting. |
Filter options
The dashboard provides dropdown filters above the summary cards.
|
Filter |
Default label |
Purpose |
|---|---|---|
|
Team |
|
Limits the results to detectors associated with a selected team |
|
Created by |
|
Limits the results to detectors created by a selected user |
|
Issue type |
|
Limits the results to a selected optimization issue |
You can combine filters to focus on a specific team, creator, or issue category.
Detectors to optimize
The Detectors to optimize tab lists detectors that have one or more optimization recommendations. You can find the following information:
|
Column |
Purpose |
|---|---|
|
|
Identifies the detector and provides access to its details. |
|
|
Shows how many alerts the detector generated during the previous seven days. |
|
|
Displays the optimization issues associated with the detector such as:
A detector can display multiple issue badges. For example, one detector might have |
|
|
Displays the expected result of addressing the issue, such as |
|
|
Identifies the user who created the detector. |
User actions
On the Detector to optimize tab, select one or more detectors to view the following actions:
-
Disable detectors: Temporarily turns off a detector without deleting it. When a detector is disabled, it stops evaluating its conditions and no longer generates alerts or notifications. This is useful when you want to pause alerting during maintenance windows, planned outages, or while troubleshooting, and then re-enable the detector afterward without losing its configuration.
-
Delete detectors: Permanently removes a detector and all of its associated alert rules and notification settings. Deleted detectors cannot be recovered. Use this option when a detector is no longer needed.
Recent optimizations
The Recent optimizations tab lists the detectors on which you have applied recommendations.
The table displays the following information:
|
Column |
Description |
|---|---|
|
|
Identifies the detector that changed. |
|
|
Identifies the alert rule that the recommendation affects. |
|
|
Describes the optimization that the user applied. |
|
|
Identifies the user who applied the recommendation. |
|
|
Displays when the user applied the recommendation. |
Detector detail view and recommendation
Select a detector from the list to view the associated issues and the AI-generated recommendation.
You can understand the issue with the detector, review the recommendation, preview the proposed change, and choose to apply the recommendation.
The preview window compares the current configuration with the proposed configuration.
Available actions on a detector:
You can do the following actions:
Apply recommendation
Select Apply recommendation to apply the proposed change to the alert rule.
Before selecting this action, you should:
-
Read the issue description.
-
Review the recommendation.
-
Check the estimated alert-volume change.
-
Review the configuration preview.
Copy SignalFlow change
Select Copy SignalFlow change from the three-dot menu to copy the proposed configuration change.
This option supports users who want to:
-
Review the change outside the panel.
-
Share the proposed change with a teammate.
-
Apply the change manually.
Dismiss recommendation
Select Dismiss recommendation when the recommendation does not apply to the detector or when you do not want to make the suggested change.
This action does not apply the proposed configuration update.
Disable alert rule
Select Disable alert rule when you want to stop the affected alert rule from generating alerts.
View detector
Select View detector to open the detector’s dedicated view. You can use this option to inspect the complete detector configuration or perform manual review.