<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I create an alert that triggers when a specific event is found for the first time in a day, but is ignored if the same event is found a second time? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-do-I-create-an-alert-that-triggers-when-a-specific-event-is/m-p/391703#M6884</link>
    <description>&lt;P&gt;What is the frequency of execution of alerts? you can search based on the time window if there are more than one events generated then set a variable as true or 1. Based on the value of variable you can have a conditional alert.&lt;/P&gt;</description>
    <pubDate>Tue, 25 Sep 2018 14:48:39 GMT</pubDate>
    <dc:creator>Vijeta</dc:creator>
    <dc:date>2018-09-25T14:48:39Z</dc:date>
    <item>
      <title>How do I create an alert that triggers when a specific event is found for the first time in a day, but is ignored if the same event is found a second time?</title>
      <link>https://community.splunk.com/t5/Alerting/How-do-I-create-an-alert-that-triggers-when-a-specific-event-is/m-p/391702#M6883</link>
      <description>&lt;P&gt;How to create alert if specific event found first time in a day and ignore creating alert if the same event found second time in day?&lt;/P&gt;

&lt;P&gt;We are indexing web services errors in Splunk. Here are some cases we are involved in.&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;We need to create an alert if we find an error text for a web service in a day. If we find the same error text for the same web service, then an alert shouldn't be created.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;This scenario will be a tricky one. If the alert finds 2 error texts: For one error text , we already raise an alert as it is the first error in a day. For another error text we need to send alert as it's new now.&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Please help me how we can handle this.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2018 13:21:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-do-I-create-an-alert-that-triggers-when-a-specific-event-is/m-p/391702#M6883</guid>
      <dc:creator>maniu1609</dc:creator>
      <dc:date>2018-09-25T13:21:17Z</dc:date>
    </item>
    <item>
      <title>Re: How do I create an alert that triggers when a specific event is found for the first time in a day, but is ignored if the same event is found a second time?</title>
      <link>https://community.splunk.com/t5/Alerting/How-do-I-create-an-alert-that-triggers-when-a-specific-event-is/m-p/391703#M6884</link>
      <description>&lt;P&gt;What is the frequency of execution of alerts? you can search based on the time window if there are more than one events generated then set a variable as true or 1. Based on the value of variable you can have a conditional alert.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2018 14:48:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-do-I-create-an-alert-that-triggers-when-a-specific-event-is/m-p/391703#M6884</guid>
      <dc:creator>Vijeta</dc:creator>
      <dc:date>2018-09-25T14:48:39Z</dc:date>
    </item>
    <item>
      <title>Re: How do I create an alert that triggers when a specific event is found for the first time in a day, but is ignored if the same event is found a second time?</title>
      <link>https://community.splunk.com/t5/Alerting/How-do-I-create-an-alert-that-triggers-when-a-specific-event-is/m-p/391704#M6885</link>
      <description>&lt;P&gt;Thanks Viji. I have set frequency as 15 mins. Could you please with an example please.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2018 14:57:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-do-I-create-an-alert-that-triggers-when-a-specific-event-is/m-p/391704#M6885</guid>
      <dc:creator>maniu1609</dc:creator>
      <dc:date>2018-09-25T14:57:49Z</dc:date>
    </item>
    <item>
      <title>Re: How do I create an alert that triggers when a specific event is found for the first time in a day, but is ignored if the same event is found a second time?</title>
      <link>https://community.splunk.com/t5/Alerting/How-do-I-create-an-alert-that-triggers-when-a-specific-event-is/m-p/391705#M6886</link>
      <description>&lt;P&gt;I think that you should use deterrence of alerts.&lt;BR /&gt;
Set the field to be used for deterring and set the suppression period to 1 day.&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5830i68340DF4E73D6553/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2018 01:01:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-do-I-create-an-alert-that-triggers-when-a-specific-event-is/m-p/391705#M6886</guid>
      <dc:creator>HiroshiSatoh</dc:creator>
      <dc:date>2018-09-27T01:01:20Z</dc:date>
    </item>
  </channel>
</rss>

