<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I stop repeated alerts? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-can-I-stop-repeated-alerts/m-p/177084#M2946</link>
    <description>&lt;P&gt;Set those three fields as the throttling fields in your Splunk alert. If all three are equal, Splunk will remain quiet. If at least one is different, Splunk will let you know.&lt;/P&gt;</description>
    <pubDate>Tue, 17 Mar 2015 22:18:32 GMT</pubDate>
    <dc:creator>martin_mueller</dc:creator>
    <dc:date>2015-03-17T22:18:32Z</dc:date>
    <item>
      <title>How can I stop repeated alerts?</title>
      <link>https://community.splunk.com/t5/Alerting/How-can-I-stop-repeated-alerts/m-p/177076#M2938</link>
      <description>&lt;P&gt;Dear all,&lt;/P&gt;

&lt;P&gt;How can I stop repeated alerts? How can I only send one alert for the same type of events in a certain period of time?&lt;BR /&gt;
Many thanks&lt;/P&gt;

&lt;P&gt;BR&lt;BR /&gt;
Victor&lt;/P&gt;</description>
      <pubDate>Sun, 15 Mar 2015 18:03:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-can-I-stop-repeated-alerts/m-p/177076#M2938</guid>
      <dc:creator>victorxbox</dc:creator>
      <dc:date>2015-03-15T18:03:22Z</dc:date>
    </item>
    <item>
      <title>Re: How can I stop repeated alerts?</title>
      <link>https://community.splunk.com/t5/Alerting/How-can-I-stop-repeated-alerts/m-p/177077#M2939</link>
      <description>&lt;P&gt;You can use Alert Throttling to stop an alert to be fired again for certain time. See this&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.2/Alert/Aboutalerts"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.2/Alert/Aboutalerts&lt;/A&gt;    (search for word Throttling)&lt;/P&gt;</description>
      <pubDate>Sun, 15 Mar 2015 19:14:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-can-I-stop-repeated-alerts/m-p/177077#M2939</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2015-03-15T19:14:58Z</dc:date>
    </item>
    <item>
      <title>Re: How can I stop repeated alerts?</title>
      <link>https://community.splunk.com/t5/Alerting/How-can-I-stop-repeated-alerts/m-p/177078#M2940</link>
      <description>&lt;P&gt;Dear Seomesoni&lt;/P&gt;

&lt;P&gt;Yes, I have tried throttle and it does work for one field. But how if  I would like throttle for multiple fields?&lt;BR /&gt;
That's mean either one of the fields does not match will trigger a new alert. How can splunk cater this problem?&lt;/P&gt;

&lt;P&gt;Many thanks&lt;BR /&gt;
BR&lt;BR /&gt;
Victor&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2015 02:19:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-can-I-stop-repeated-alerts/m-p/177078#M2940</guid>
      <dc:creator>victorxbox</dc:creator>
      <dc:date>2015-03-16T02:19:18Z</dc:date>
    </item>
    <item>
      <title>Re: How can I stop repeated alerts?</title>
      <link>https://community.splunk.com/t5/Alerting/How-can-I-stop-repeated-alerts/m-p/177079#M2941</link>
      <description>&lt;P&gt;What is your alert definition? Could you please explain how you're currently using multiple fields to trigger alert?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2015 21:03:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-can-I-stop-repeated-alerts/m-p/177079#M2941</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2015-03-16T21:03:04Z</dc:date>
    </item>
    <item>
      <title>Re: How can I stop repeated alerts?</title>
      <link>https://community.splunk.com/t5/Alerting/How-can-I-stop-repeated-alerts/m-p/177080#M2942</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;   Run a search and save as it  alert .

  Then go to    Settings --&amp;gt; Searches ,Reports , and Alerts

  Click to the Alert that you want it  stop to trigger . In the opened form , check  Schedule this search  under  Schedule and alert . 

  Then check    After triggering the alert , don't trigger it again   for that is under Throttling in drop down .

  For alert sending check    Enable Send email   in section   Alert actions   and fill the fields which are there.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 17 Mar 2015 09:26:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-can-I-stop-repeated-alerts/m-p/177080#M2942</guid>
      <dc:creator>chimell</dc:creator>
      <dc:date>2015-03-17T09:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: How can I stop repeated alerts?</title>
      <link>https://community.splunk.com/t5/Alerting/How-can-I-stop-repeated-alerts/m-p/177081#M2943</link>
      <description>&lt;P&gt;hi victor,&lt;BR /&gt;
I do not know if this will help you, but it's like this I proceeded to manage my alerts.&lt;BR /&gt;
• For the resolution of your of your problem if this is the case the following steps:&lt;BR /&gt;
       1- go to &lt;CODE&gt;settings&lt;/CODE&gt;,&lt;BR /&gt;
       2- then pick &lt;CODE&gt;Searches, reports, and alerts&lt;/CODE&gt;&lt;BR /&gt;
       3- check the &lt;CODE&gt;Schedule this search&lt;/CODE&gt; option&lt;BR /&gt;
       4- look &lt;CODE&gt;Alert&lt;/CODE&gt; tab and check the &lt;CODE&gt;condition&lt;/CODE&gt; and choose the one you want and &lt;CODE&gt;Alert Mode&lt;/CODE&gt; (choose the corresponding one)&lt;BR /&gt;
        5- Finally check &lt;CODE&gt;Throttling&lt;/CODE&gt; (to limit the flow of alert)&lt;BR /&gt;
Test and let me know if it works.&lt;BR /&gt;
please forgive my english.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Mar 2015 09:30:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-can-I-stop-repeated-alerts/m-p/177081#M2943</guid>
      <dc:creator>gyslainlatsa</dc:creator>
      <dc:date>2015-03-17T09:30:18Z</dc:date>
    </item>
    <item>
      <title>Re: How can I stop repeated alerts?</title>
      <link>https://community.splunk.com/t5/Alerting/How-can-I-stop-repeated-alerts/m-p/177082#M2944</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;

&lt;P&gt;Thanks for all of your replies. Maybe I further elaborate my problem.&lt;BR /&gt;
I would like to use Splunk to replace the log aggregation feature that I am now using in ArcSight.&lt;BR /&gt;
Below is the example of the log aggregation in Arcsight&lt;BR /&gt;
In ArcSight, multiple fields were selected as the aggregated items which are "src_ip", "dst_ip" and "attack_name". &lt;BR /&gt;
Once there is an attack log from the device. For example,&lt;BR /&gt;
src_ip=1.1.1.1  dst=2.2.2.2  attack_name=brute_force&lt;BR /&gt;
The arcsight will trigger an alert and send an email notification&lt;/P&gt;

&lt;P&gt;When there is an other attack log with the same "src_ip", "dst_ip" and "attack_name"&lt;BR /&gt;
src_ip=1.1.1.1  dst=2.2.2.2  attack_name=brute_force&lt;BR /&gt;
The arcsight &lt;STRONG&gt;WILL NOT&lt;/STRONG&gt;  trigger any alert and email notification&lt;/P&gt;

&lt;P&gt;But if one or more of the fields in the attack log are different.&lt;BR /&gt;
A new alert and email notification will be triggered .&lt;/P&gt;

&lt;P&gt;Can I build the similar logic in Splunk?&lt;/P&gt;

&lt;P&gt;Many thanks&lt;BR /&gt;
Victor&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:10:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-can-I-stop-repeated-alerts/m-p/177082#M2944</guid>
      <dc:creator>victorxbox</dc:creator>
      <dc:date>2020-09-28T19:10:29Z</dc:date>
    </item>
    <item>
      <title>Re: How can I stop repeated alerts?</title>
      <link>https://community.splunk.com/t5/Alerting/How-can-I-stop-repeated-alerts/m-p/177083#M2945</link>
      <description>&lt;P&gt;I would like to use Splunk to replace the log aggregation feature that I am now using in ArcSight.&lt;BR /&gt;
Below is the example of the log aggregation in Arcsight&lt;BR /&gt;
In ArcSight, multiple fields were selected as the aggregated items which are "src_ip", "dst_ip" and "attack_name". &lt;BR /&gt;
Once there is an attack log from the device. For example,&lt;BR /&gt;
src_ip=1.1.1.1 dst=2.2.2.2 attack_name=brute_force&lt;BR /&gt;
The arcsight will trigger an alert and send an email notification&lt;/P&gt;

&lt;P&gt;When there is an other attack log with the same "src_ip", "dst_ip" and "attack_name"&lt;BR /&gt;
src_ip=1.1.1.1 dst=2.2.2.2 attack_name=brute_force&lt;BR /&gt;
The arcsight WILL NOT trigger any alert and email notification&lt;/P&gt;

&lt;P&gt;But if one or more of the fields in the attack log are different.&lt;BR /&gt;
A new alert and email notification will be triggered .&lt;/P&gt;

&lt;P&gt;Can I build the similar logic in Splunk?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:10:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-can-I-stop-repeated-alerts/m-p/177083#M2945</guid>
      <dc:creator>victorxbox</dc:creator>
      <dc:date>2020-09-28T19:10:32Z</dc:date>
    </item>
    <item>
      <title>Re: How can I stop repeated alerts?</title>
      <link>https://community.splunk.com/t5/Alerting/How-can-I-stop-repeated-alerts/m-p/177084#M2946</link>
      <description>&lt;P&gt;Set those three fields as the throttling fields in your Splunk alert. If all three are equal, Splunk will remain quiet. If at least one is different, Splunk will let you know.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Mar 2015 22:18:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-can-I-stop-repeated-alerts/m-p/177084#M2946</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2015-03-17T22:18:32Z</dc:date>
    </item>
  </channel>
</rss>

