<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to set up Alert Throttle for multiple hosts? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-to-set-up-Alert-Throttle-for-multiple-hosts/m-p/625013#M14595</link>
    <description>&lt;P&gt;Hi All,&lt;BR /&gt;&lt;BR /&gt;We are trying to se&lt;SPAN&gt;tup CPU alerts for few servers and we are looking to throttle the alerts to reduce the noise.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AKG11_1-1671644585967.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23114iA2D1A1AC72E78084/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AKG11_1-1671644585967.png" alt="AKG11_1-1671644585967.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Option 1:&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;Trigger = Once&lt;BR /&gt;Throttle = Checked&amp;nbsp;&lt;BR /&gt;Suppress trigger for = 4 hours&lt;BR /&gt;If I select this option then suppose there is an issue for one host and alert is triggered. it won't generate another alert for 4 hrs. but I think we are going to miss if there is an issue with another host during that 4 hrs.&amp;nbsp; is it ?&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Option 2:&lt;/STRONG&gt;&lt;BR /&gt;Trigger = For Each Results&lt;BR /&gt;Throttle = Checked&amp;nbsp;&lt;BR /&gt;Suppress results containing field value = host&lt;BR /&gt;Suppress trigger for = 4 hours&lt;/P&gt;
&lt;P&gt;If we choose this option issue is it there are 10 host it will generate 10 separate alert for each host.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Can some one guide what will be the better way to setup this alert ?&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 22 Dec 2022 16:41:18 GMT</pubDate>
    <dc:creator>AKG11</dc:creator>
    <dc:date>2022-12-22T16:41:18Z</dc:date>
    <item>
      <title>How to set up Alert Throttle for multiple hosts?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-set-up-Alert-Throttle-for-multiple-hosts/m-p/625013#M14595</link>
      <description>&lt;P&gt;Hi All,&lt;BR /&gt;&lt;BR /&gt;We are trying to se&lt;SPAN&gt;tup CPU alerts for few servers and we are looking to throttle the alerts to reduce the noise.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AKG11_1-1671644585967.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23114iA2D1A1AC72E78084/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AKG11_1-1671644585967.png" alt="AKG11_1-1671644585967.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Option 1:&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;Trigger = Once&lt;BR /&gt;Throttle = Checked&amp;nbsp;&lt;BR /&gt;Suppress trigger for = 4 hours&lt;BR /&gt;If I select this option then suppose there is an issue for one host and alert is triggered. it won't generate another alert for 4 hrs. but I think we are going to miss if there is an issue with another host during that 4 hrs.&amp;nbsp; is it ?&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Option 2:&lt;/STRONG&gt;&lt;BR /&gt;Trigger = For Each Results&lt;BR /&gt;Throttle = Checked&amp;nbsp;&lt;BR /&gt;Suppress results containing field value = host&lt;BR /&gt;Suppress trigger for = 4 hours&lt;/P&gt;
&lt;P&gt;If we choose this option issue is it there are 10 host it will generate 10 separate alert for each host.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Can some one guide what will be the better way to setup this alert ?&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2022 16:41:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-set-up-Alert-Throttle-for-multiple-hosts/m-p/625013#M14595</guid>
      <dc:creator>AKG11</dc:creator>
      <dc:date>2022-12-22T16:41:18Z</dc:date>
    </item>
  </channel>
</rss>

