Optimize detectors

Detector Optimization reviews existing detectors and identifies opportunities to improve monitoring quality.

Note: In the Controlled Availability release stage, Splunk products may have limitations on customer access, features, maturity, and regional availability. For additional information on Controlled Availability please contact your Splunk representative.

Detector optimization is a built-in Splunk Observability Cloud experience that reviews existing detectors and identifies opportunities to improve monitoring quality.

Managing large numbers of detectors without clear guidance on which ones need attention can result in:

  • Alert fatigue caused by noisy or flapping detectors.

  • Important alerts not reaching a notification recipient.

  • Detectors monitoring inactive or outdated data.

  • Long-term muted or unused detectors remaining in the environment.

  • Excessive reliance on monitoring experts to identify configuration issues.

  • Reduced trust in alerts and slower incident response.

Detector optimization provides a prioritized, guided way to improve detector quality and reduce unnecessary alert noise. It helps you:

  • find detectors that generate excessive or low-value alerts.

  • identify stale, inactive, muted, or incompletely configured detectors.

  • understand why a detector was flagged.

  • review the expected impact of a recommended change.

  • apply supported fixes or dismiss recommendations.

  • review recently applied optimizations.

View the detectors that can be optimized

Use Detector optimization to view detectors that have optimization recommendations.

  1. Open Splunk Observability Cloud.
  2. Go to Alerts > Detectors.
  3. On the Detectors page, select the Detector optimization tab.

Detector optimization details

Reference information about detector issues, filters, optimization recommendations, and available actions.

The Detector optimization page helps you find detectors and alert rules that need configuration cleanup or alert-noise reduction.

Detector optimization page

Summary card details

The summary cards provide a quick count of the most important detector issues found during the latest optimization scan:

Summary card

What the card represents

Why it matters

Detector with no duration

Displays the number of detectors that do not define a sustained duration, such as lasting before an alert fires.

Without a duration, a detector can fire on short-lived metric spikes or temporary data changes. This can create noisy alerts that do not represent a sustained problem.

Detector with same fire/clear threshold

Displays the number of detectors where the fire threshold and clear threshold are the same, or where no separate clear threshold is configured.

When the monitored value hovers around a single threshold, the alert can repeatedly fire and clear. This flapping behavior makes incidents harder to trust and increases alert noise.

Detector with alert severity misalignment

Displays the number of detectors whose severity distribution appears misaligned with actual alert behavior, for example too many Critical or Major alerts, severity inflation, or thresholds that keep alerts in a non-normal state too often.

Misaligned severity can cause teams to treat low-priority symptoms as urgent incidents or miss the intended escalation path. It can also reduce trust in Critical and Major alerts.

Detectors muted for 30d+

Displays the number of detectors that have been muted for at least 30 days, or whose alerts have been fully suppressed over the long-term muted lookback period.

Long-term muted detectors usually indicate alert rules that are no longer useful, are too noisy, or have been intentionally suppressed instead of fixed. Keeping them muted can hide monitoring gaps and add stale configuration clutter.

Detectors with no data for 7d+

Displays the number of detectors whose monitored metric or signal has had no active data for at least 7 days. These detectors might also have no recent alert activity because the underlying data is no longer being reported.

A detector with no incoming data cannot alert meaningfully. It can create a false sense of coverage, especially when the metric, service, host, or dimension it monitors has been removed, renamed, or stopped reporting.

Filter options

The dashboard provides dropdown filters above the summary cards.

Filter

Default label

Purpose

Team

Team: All

Limits the results to detectors associated with a selected team

Created by

Created by: All

Limits the results to detectors created by a selected user

Issue type

Issue: All

Limits the results to a selected optimization issue

You can combine filters to focus on a specific team, creator, or issue category.

Detectors to optimize

The Detectors to optimize tab lists detectors that have one or more optimization recommendations. You can find the following information:

Column

Purpose

Detector name

Identifies the detector and provides access to its details.

Alert count (7d)

Shows how many alerts the detector generated during the previous seven days.

Issue

Displays the optimization issues associated with the detector such as:

  • No duration

  • Same fire/clear thresholds

  • Severity misalignment

A detector can display multiple issue badges. For example, one detector might have No duration, Same fire/clear thresholds, and Severity misalignment.

Projected impact

Displays the expected result of addressing the issue, such as <1% alert reduction, 60% alert reduction, or Fewer high priority alerts

Created by

Identifies the user who created the detector.

User actions

On the Detector to optimize tab, select one or more detectors to view the following actions:

  • Disable detectors: Temporarily turns off a detector without deleting it. When a detector is disabled, it stops evaluating its conditions and no longer generates alerts or notifications. This is useful when you want to pause alerting during maintenance windows, planned outages, or while troubleshooting, and then re-enable the detector afterward without losing its configuration.

  • Delete detectors: Permanently removes a detector and all of its associated alert rules and notification settings. Deleted detectors cannot be recovered. Use this option when a detector is no longer needed.

Detector optimization bulk actions

Recent optimizations

The Recent optimizations tab lists the detectors on which you have applied recommendations.

Detector recent optimization

The table displays the following information:

Column

Description

Detector name

Identifies the detector that changed.

Alert rule

Identifies the alert rule that the recommendation affects.

Applied recommendation

Describes the optimization that the user applied.

Applied by

Identifies the user who applied the recommendation.

Date applied

Displays when the user applied the recommendation.

Detector detail view and recommendation

Select a detector from the list to view the associated issues and the AI-generated recommendation.

You can understand the issue with the detector, review the recommendation, preview the proposed change, and choose to apply the recommendation.

The preview window compares the current configuration with the proposed configuration.

Detector optimization detailed view and recommendation

Available actions on a detector:

You can do the following actions:

Apply recommendation

Select Apply recommendation to apply the proposed change to the alert rule.

Before selecting this action, you should:

  1. Read the issue description.

  2. Review the recommendation.

  3. Check the estimated alert-volume change.

  4. Review the configuration preview.

Copy SignalFlow change

Select Copy SignalFlow change from the three-dot menu to copy the proposed configuration change.

This option supports users who want to:

  • Review the change outside the panel.

  • Share the proposed change with a teammate.

  • Apply the change manually.

Dismiss recommendation

Select Dismiss recommendation when the recommendation does not apply to the detector or when you do not want to make the suggested change.

This action does not apply the proposed configuration update.

Disable alert rule

Select Disable alert rule when you want to stop the affected alert rule from generating alerts.

View detector

Select View detector to open the detector’s dedicated view. You can use this option to inspect the complete detector configuration or perform manual review.