> ## Documentation Index
> Fetch the complete documentation index at: https://docs-xcor.paloaltonetworks.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a discard notifier

> Create and route to a discard notifier with Palo Alto Networks Cortex XCOR, Chronoctl, or Terraform.

In Palo Alto Networks Cortex XCOR, the discard notifier discards all
notifications. Use it to silence a subset of routes without deleting them, hold a place
in a notification policy while you restructure routing, or test notification policy
behavior without delivering alerts.

## Terminology

Cortex XCOR includes a discard notifier type on the
[notifier form](/investigate/alerts/notifications/notifiers#create-a-notifier).
[Chronoctl](/tooling/chronoctl) and the Cortex XCOR API represent it with
`discard: true`. The [Terraform](/tooling/infrastructure/terraform) provider declares a
`chronosphere_blackhole_alert_notifier` resource because it has no
`chronosphere_discard_*` resource.

For the discard notifier type, the following text appears in the notifier form:

```text wrap theme={null}
A discard notifier, also known as a blackhole notifier, does not send any notifications.
```

A discard notifier drops notifications before they leave the alerting pipeline. Don't set
`discard: true` on the same notifier as another integration, for example `email` or
`slack`.

An [email notifier](/investigate/alerts/notifications/notifiers/email) with a
destination such as `blackhole@example.com` still uses the email integration. It isn't
a discard notifier. To silence alerts without email delivery, create a discard notifier
and add it to a [notification policy](/investigate/alerts/notifications/policies).

Select from the following methods to create a discard notifier.

<Tabs>
  <Tab title="Web" id="create-discard-notifier">
    To create a discard notifier:

    1. In the navigation menu, select
       **<Icon icon="bell" /> Alerting <span aria-label="and then">></span> Notifiers**.
    2. Click **Create notifier**.
    3. Enter a descriptive name for the notifier.
    4. Select **Discard** as the type of notifier you want to create.
    5. Click **Save**.

    A discard notifier has no delivery settings to configure.

    When you edit an existing notifier and switch to the discard notifier type, saving
    replaces the previous configuration. That configuration can't be recovered.
  </Tab>

  <Tab title="Chronoctl" id="discard-chronoctl">
    To create one or more notifiers using [Chronoctl](/tooling/chronoctl), create a YAML file
    that defines them and apply the configuration to your instance.

    <Note>
      You can use the `notifiers scaffold` command to generate an example notifier, and
      then copy the resource definition for your notifier type:

      ```shell theme={null}
      chronoctl notifiers scaffold
      ```
    </Note>

    1. Define the resource definition for your discard notifier:

       ```yaml Chronoctl example icon="square-terminal" /NAME/ /SLUG/ theme={null}
       api_version: v1/config
       kind: Notifier
       spec:
         name: NAME
         slug: SLUG
         discard: true
       ```

       Replace the following:

       * *`NAME`*: A descriptive name, such as `Example discard`.
       * *`SLUG`*: A unique identifier, such as `example-discard`.

    2. Apply the changes:

       ```shell /FILE_NAME/ theme={null}
       chronoctl apply -f FILE_NAME.yaml
       ```

       Replace *`FILE_NAME`* with the name of your notifier YAML file.
  </Tab>

  <Tab title="Terraform" id="discard-terraform">
    To create a discard notifier:

    1. Create a discard notifier with [Terraform](/tooling/infrastructure/terraform) by using the
       `chronosphere_blackhole_alert_notifier` type followed by a name in a resource
       declaration:

       ```terraform Terraform example icon="square-terminal" theme={null}
       resource "chronosphere_blackhole_alert_notifier" "discard" {
         name = "Example discard"
       }
       ```

    2. Run `terraform apply` to create the notifier resource.

       ```shell theme={null}
       terraform apply
       ```
  </Tab>

  <Tab title="API" id="discard-api">
    To complete this action with the Cortex XCOR API, set `discard` to `true` in the
    [`CreateNotifier`](/tooling/api-info/definition/operations/CreateNotifier) endpoint.

    Because the Cortex XCOR API requires authentication, include an API token with your
    `curl` request, as shown in the following example. For more details, see
    [Create an API token](/tooling/api-info#create-an-api-token).

    ```shell /"TOKEN"/ /INSTANCE/ /METHOD/ /ENDPOINT_PATH/ theme={null}
    export CHRONOSPHERE_API_TOKEN="TOKEN"
    export CHRONOSPHERE_DOMAIN="INSTANCE.chronosphere.io"

    curl -H "API-Token: ${CHRONOSPHERE_API_TOKEN}" \
         -X METHOD "https://${CHRONOSPHERE_DOMAIN}/ENDPOINT_PATH"
    ```

    Replace the following:

    * *`TOKEN`*: Your API token.
    * *`INSTANCE`*: The subdomain name for your organization's Cortex XCOR instance.
    * *`METHOD`*: The HTTP method to use with the request, such as `GET` or `POST`.
    * *`ENDPOINT_PATH`*: The specific endpoint you want to access.
  </Tab>
</Tabs>

## Route alerts to a discard notifier

After you create a discard notifier, attach it to a
[notification policy](/investigate/alerts/notifications/policies) so matching monitors
send warning or critical alerts to that notifier.

Select from the following methods to route alerts to a discard notifier.

<Tabs>
  <Tab title="Web" id="route-discard-web">
    1. In the navigation menu, select
       **<Icon icon="bell" /> Alerting <span aria-label="and then">></span> Notification Policies**.
    2. Create a notification policy or open the policy you want to change.
    3. For **Warning alert notifiers**, **Critical alert notifiers**, or both, select your
       discard notifier.
    4. Click **Save**.

    Monitors that use this notification policy send notifications to the discard notifier
    for the severities you configured.
  </Tab>

  <Tab title="Chronoctl" id="route-discard-chronoctl">
    1. Reference the discard notifier by slug in the policy's `notifier_slugs` lists. For
       example, a policy that sends both warning and critical alerts to the discard notifier
       with slug `example-discard`:

       ```yaml Chronoctl example icon="square-terminal" /example-discard/ theme={null}
       api_version: v1/config
       kind: NotificationPolicy
       spec:
         slug: silence-noisy-alerts
         name: Silence noisy alerts
         routes:
           defaults:
             warn:
               notifier_slugs:
                 - example-discard
             critical:
               notifier_slugs:
                 - example-discard
       ```

    2. Apply the policy YAML:

       ```shell /FILE_NAME/ theme={null}
       chronoctl apply -f FILE_NAME.yaml
       ```

       Replace *`FILE_NAME`* with the name of your notification policy YAML file.
  </Tab>

  <Tab title="Terraform" id="route-discard-terraform">
    1. Add the discard notifier to `route` blocks on a
       `chronosphere_notification_policy` resource:

       ```terraform Terraform example icon="square-terminal" theme={null}
       resource "chronosphere_notification_policy" "silence_noisy" {
         name = "Silence noisy alerts"

         route {
           severity  = "warn"
           notifiers = [chronosphere_blackhole_alert_notifier.discard.id]
         }

         route {
           severity  = "critical"
           notifiers = [chronosphere_blackhole_alert_notifier.discard.id]
         }
       }
       ```

    2. Run `terraform apply` to update the notification policy resource.

       ```shell theme={null}
       terraform apply
       ```
  </Tab>
</Tabs>


## Related topics

- [Notifiers](/investigate/alerts/notifications/notifiers.md)
- [CreateNotifier](/tooling/api-info/definition/operations/CreateNotifier.md)
- [Create an Opsgenie notifier](/investigate/alerts/notifications/notifiers/opsgenie.md)
- [Create a Slack notifier](/investigate/alerts/notifications/notifiers/slack.md)
- [Notifier connections](/investigate/alerts/notifications/external-connections.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.