<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Alerts suppression issue? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Splunk-Alerts-suppression-issue/m-p/560816#M10682</link>
    <description>&lt;P&gt;FWIW, 600 seconds is 10 minutes, not 5.&lt;/P&gt;&lt;P&gt;You say you accepted an answer, but no answer is so marked.&lt;/P&gt;</description>
    <pubDate>Mon, 26 Jul 2021 15:22:23 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-07-26T15:22:23Z</dc:date>
    <item>
      <title>Splunk Alerts suppression issue?</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Alerts-suppression-issue/m-p/560350#M10671</link>
      <description>&lt;P&gt;We have a Splunk Alert set up with the following configuration:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SETTINGS&lt;/STRONG&gt;&lt;BR /&gt;Alert type = Scheduled (Run on Cron Schedule)&lt;BR /&gt;Time Range = Today&lt;BR /&gt;Cron Expression = *****&lt;BR /&gt;Expires = 24 hours&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;TRIGGER CONDITIONS&lt;/STRONG&gt;&lt;BR /&gt;Trigger alert when = Number of Results &amp;gt; 0&lt;BR /&gt;Trigger = Once&lt;BR /&gt;Throttle = Ticked&lt;BR /&gt;Suppress triggering for = 1 day&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;TRIGGER ACTIONS&lt;/STRONG&gt;&lt;BR /&gt;When triggered&lt;BR /&gt;- Add to Triggered Alerts&lt;BR /&gt;- Send email&lt;/P&gt;&lt;P&gt;The issue that we are experiencing is that if we have 3 events occur at different times throughout the day, we are only receiving an email for the first one.&amp;nbsp; Also, the following day (within the 24 hour period from the previous alert) we are not receiving any email notifications.&amp;nbsp; In all cases if I select the Splunk Alert and view the results I see all the events shown here, including those for which no email notification was received..&lt;/P&gt;&lt;P&gt;I believe the issue here has to do with the following settings:&lt;/P&gt;&lt;P&gt;Trigger = Once&lt;BR /&gt;Throttle = Ticked&lt;BR /&gt;Suppress triggering for = 1 day&lt;/P&gt;&lt;P&gt;From the Splunk documentation it is not clear whether all Splunk alerts would get suppressed after the first one, or just repeated Splunk Alerts for the same event.&amp;nbsp; I am assuming that it's the former as this would explain why we don't see any further email notifications until the 1 day / 24 hour period expires(?)&lt;/P&gt;&lt;P&gt;I think changing the settings to the following:&lt;/P&gt;&lt;P&gt;Trigger = For each result&lt;BR /&gt;Throttle = Ticked&lt;BR /&gt;Suppress triggering for = 1 day&lt;/P&gt;&lt;P&gt;Will at least mean that we receive only one event in each email notification (for simultaneous alerts ... another issue that exists) but will not fix the suppressed email notifications.&amp;nbsp; Furthermore, removing the Throttle seems to just continuously alert on the same event.&lt;/P&gt;&lt;P&gt;I want to keep the "Scheduled Alert" type (rather than "Realtime") due to the set-up that we have here and also I am unable to play around too much with the configuration in test as we do not have email notifications in this environment (only in our live environment).&lt;/P&gt;&lt;P&gt;The goal, in case it's not yet clear from the above, is to receive a single email notification for each event.&amp;nbsp; Can you please advise / suggest the correct change that I should make to achieve this?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jul 2021 12:52:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Alerts-suppression-issue/m-p/560350#M10671</guid>
      <dc:creator>L1mLam</dc:creator>
      <dc:date>2021-07-21T12:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Alerts suppression issue?</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Alerts-suppression-issue/m-p/560366#M10672</link>
      <description>&lt;P&gt;Throttling a once-per-search alert prevents it from triggering again until the throttle period expires.&amp;nbsp; If you switch the alert to one-per-event then you can select a field (host, for example) on which to base the throttling.&amp;nbsp; New alerts for the same field value will not trigger, but a different value will trigger an alert.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jul 2021 15:24:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Alerts-suppression-issue/m-p/560366#M10672</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-07-21T15:24:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Alerts suppression issue?</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Alerts-suppression-issue/m-p/560811#M10680</link>
      <description>&lt;P&gt;Apologies for the delayed response ... due to technical issues logging into my Splunk account.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your suggestion.&amp;nbsp; I have now accepted this and made some adjustments also to the cron schedule (from **** to&amp;nbsp;*/5 * * * *), with the addition of a "Suppress triggering for 600 seconds" (i.e. 5 mins) added in too.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trialling this solution over this next week to see if any of our (infrequent) alert events result in this Splunk Alert correctly being triggered.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jul 2021 15:00:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Alerts-suppression-issue/m-p/560811#M10680</guid>
      <dc:creator>L1mLam</dc:creator>
      <dc:date>2021-07-26T15:00:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Alerts suppression issue?</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Alerts-suppression-issue/m-p/560812#M10681</link>
      <description>&lt;P&gt;*suggestion&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jul 2021 15:01:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Alerts-suppression-issue/m-p/560812#M10681</guid>
      <dc:creator>L1mLam</dc:creator>
      <dc:date>2021-07-26T15:01:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Alerts suppression issue?</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Alerts-suppression-issue/m-p/560816#M10682</link>
      <description>&lt;P&gt;FWIW, 600 seconds is 10 minutes, not 5.&lt;/P&gt;&lt;P&gt;You say you accepted an answer, but no answer is so marked.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jul 2021 15:22:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Alerts-suppression-issue/m-p/560816#M10682</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-07-26T15:22:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Alerts suppression issue?</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Alerts-suppression-issue/m-p/560822#M10683</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;that's a very good point!&amp;nbsp; 600 secs is 10 mins - apologies for the confusion.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;I used that example as someone provided this to me within my organisation but you're right that this should be set to 300 for 5 mins.&amp;nbsp; Incidentally, for the suppression period I don't think that it makes much difference as both values should ensure that the next alert is outside of the 5 minute cron schedule checkpoint window.&lt;/P&gt;&lt;P&gt;I didn't yet "Accept as Solution" until I have validated this in my test environment, as alluded in my earlier comment.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jul 2021 15:42:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Alerts-suppression-issue/m-p/560822#M10683</guid>
      <dc:creator>L1mLam</dc:creator>
      <dc:date>2021-07-26T15:42:51Z</dc:date>
    </item>
  </channel>
</rss>

