<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Send alert once if message doesn't change in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-to-send-alert-once-if-message-doesn-t-change/m-p/621677#M14522</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;This is my configuration:&lt;/P&gt;&lt;P&gt;Sorry it's in french but the function is same as in english. Do you find where I can do it please?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Julia1231_0-1669114910106.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22586i031F7B1CD61A2C1D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Julia1231_0-1669114910106.png" alt="Julia1231_0-1669114910106.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 22 Nov 2022 11:03:26 GMT</pubDate>
    <dc:creator>Julia1231</dc:creator>
    <dc:date>2022-11-22T11:03:26Z</dc:date>
    <item>
      <title>How to send alert once if message doesn't change?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-send-alert-once-if-message-doesn-t-change/m-p/621671#M14520</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I am doing the sending alert if a machine has no activity in the span = 1h.&lt;/P&gt;
&lt;P&gt;I configure to send it each hour. The thing is if the machine has no activity at 7:00, it will send the alert every hour (7h, 8h, 9h, etc) saying the same message that the machine has no activity at 7:00&lt;/P&gt;
&lt;P&gt;Is anyway to send it once if the message is always the same (in this case, machine has no activity at 7:00).&lt;/P&gt;
&lt;P&gt;If the machine is restarted, it has activities from 10:00 - 15:00, then it downs, I will receive an alert saying that machine has no activity at 15:00)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advanced.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 16:01:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-send-alert-once-if-message-doesn-t-change/m-p/621671#M14520</guid>
      <dc:creator>Julia1231</dc:creator>
      <dc:date>2022-11-22T16:01:14Z</dc:date>
    </item>
    <item>
      <title>Re: Send alert once if message doesn't change</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-send-alert-once-if-message-doesn-t-change/m-p/621674#M14521</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/245583"&gt;@Julia1231&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;did you tried to configure throttling for your alert?&lt;/P&gt;&lt;P&gt;You can do this in the alert definition page.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 10:47:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-send-alert-once-if-message-doesn-t-change/m-p/621674#M14521</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-11-22T10:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: Send alert once if message doesn't change</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-send-alert-once-if-message-doesn-t-change/m-p/621677#M14522</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;This is my configuration:&lt;/P&gt;&lt;P&gt;Sorry it's in french but the function is same as in english. Do you find where I can do it please?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Julia1231_0-1669114910106.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22586i031F7B1CD61A2C1D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Julia1231_0-1669114910106.png" alt="Julia1231_0-1669114910106.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 11:03:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-send-alert-once-if-message-doesn-t-change/m-p/621677#M14522</guid>
      <dc:creator>Julia1231</dc:creator>
      <dc:date>2022-11-22T11:03:26Z</dc:date>
    </item>
    <item>
      <title>Re: Send alert once if message doesn't change</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-send-alert-once-if-message-doesn-t-change/m-p/621678#M14523</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/245583"&gt;@Julia1231&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you have to flag "Throttle" and define a time period that the alert will not be fired.&lt;/P&gt;&lt;P&gt;Only for the next time if you go in the address bar of your browser, replace "fr-FR" with "en-US", you'll have the dashboard in english, I'm italian and I usually have the same problem.&lt;/P&gt;&lt;P&gt;ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 11:07:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-send-alert-once-if-message-doesn-t-change/m-p/621678#M14523</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-11-22T11:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: Send alert once if message doesn't change</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-send-alert-once-if-message-doesn-t-change/m-p/621703#M14527</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;thank you.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So what I understand, because the Throttle goes with the Suppress triggering for (time), I can only suppress for the period that I define here.&lt;/P&gt;&lt;P&gt;For example if I put the suppress triggering for 3 hours, I will always receive the same email each 3h? It can reduce the number of duplicate email sent but cannot avoid, is it true?&lt;BR /&gt;And even if my machine is restarted, it has activity again, there is always the alert sent for inform a fault in the pass.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Julia&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 14:26:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-send-alert-once-if-message-doesn-t-change/m-p/621703#M14527</guid>
      <dc:creator>Julia1231</dc:creator>
      <dc:date>2022-11-22T14:26:17Z</dc:date>
    </item>
    <item>
      <title>Re: Send alert once if message doesn't change</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-send-alert-once-if-message-doesn-t-change/m-p/621807#M14528</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/245583"&gt;@Julia1231&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;my hint is to analyze throttle feature to use it at the best.&lt;/P&gt;&lt;P&gt;Otherwise a much more complicated workaround is to to write all your alerts in a summary index (as e.g. ES does) and then use this summary index to exclude the triggered alerts from results, but, as I said, it isn't so immediate to realize.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 07:48:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-send-alert-once-if-message-doesn-t-change/m-p/621807#M14528</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-11-23T07:48:53Z</dc:date>
    </item>
  </channel>
</rss>

