<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trigger real time alert once in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Trigger-real-time-alert-once/m-p/59944#M813</link>
    <description>&lt;P&gt;my understanding of throttling is that it's not the same as alerting once per event.&lt;/P&gt;

&lt;P&gt;eg, if i have throttling set to no more than once per minute,&lt;BR /&gt;
and an event occurs twice, in two consecutive seconds,&lt;BR /&gt;
i want to get exactly two alerts.&lt;/P&gt;

&lt;P&gt;i'm still looking for an answer to the poster's question.&lt;/P&gt;</description>
    <pubDate>Wed, 30 Nov 2011 21:05:11 GMT</pubDate>
    <dc:creator>elenzil</dc:creator>
    <dc:date>2011-11-30T21:05:11Z</dc:date>
    <item>
      <title>Trigger real time alert once</title>
      <link>https://community.splunk.com/t5/Alerting/Trigger-real-time-alert-once/m-p/59941#M810</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I was wondering how I can make Splunk notify me of an alert in real time only once. For example, if I'm running a real time search for when a firewall is turned off, how do I keep Splunk from alerting me for the same results repeatedly (which looks like it happens 3 to 4 times a minute)?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 18 Aug 2011 05:29:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Trigger-real-time-alert-once/m-p/59941#M810</guid>
      <dc:creator>samiomer</dc:creator>
      <dc:date>2011-08-18T05:29:42Z</dc:date>
    </item>
    <item>
      <title>Re: Trigger real time alert once</title>
      <link>https://community.splunk.com/t5/Alerting/Trigger-real-time-alert-once/m-p/59942#M811</link>
      <description>&lt;P&gt;hi samiomer&lt;/P&gt;

&lt;P&gt;Alert throttling can be setup like written &lt;A href="http://docs.splunk.com/Documentation/Splunk/4.2.3/ReleaseNotes/Alertthrottlingandexpiration"&gt;in the docs&lt;/A&gt; or for pre 4.2 splunk with the app &lt;A href="http://splunk-base.splunk.com/apps/22379/alertthrottle"&gt;alert throttle&lt;/A&gt;.&lt;/P&gt;

&lt;P&gt;regards&lt;/P&gt;</description>
      <pubDate>Thu, 18 Aug 2011 06:27:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Trigger-real-time-alert-once/m-p/59942#M811</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2011-08-18T06:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: Trigger real time alert once</title>
      <link>https://community.splunk.com/t5/Alerting/Trigger-real-time-alert-once/m-p/59943#M812</link>
      <description>&lt;P&gt;Thanks. That helped &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Aug 2011 13:44:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Trigger-real-time-alert-once/m-p/59943#M812</guid>
      <dc:creator>samiomer</dc:creator>
      <dc:date>2011-08-18T13:44:39Z</dc:date>
    </item>
    <item>
      <title>Re: Trigger real time alert once</title>
      <link>https://community.splunk.com/t5/Alerting/Trigger-real-time-alert-once/m-p/59944#M813</link>
      <description>&lt;P&gt;my understanding of throttling is that it's not the same as alerting once per event.&lt;/P&gt;

&lt;P&gt;eg, if i have throttling set to no more than once per minute,&lt;BR /&gt;
and an event occurs twice, in two consecutive seconds,&lt;BR /&gt;
i want to get exactly two alerts.&lt;/P&gt;

&lt;P&gt;i'm still looking for an answer to the poster's question.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2011 21:05:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Trigger-real-time-alert-once/m-p/59944#M813</guid>
      <dc:creator>elenzil</dc:creator>
      <dc:date>2011-11-30T21:05:11Z</dc:date>
    </item>
    <item>
      <title>Re: Trigger real time alert once</title>
      <link>https://community.splunk.com/t5/Alerting/Trigger-real-time-alert-once/m-p/59945#M814</link>
      <description>&lt;P&gt;Only 4.3 supports "once per event".&lt;BR /&gt;
Anyone found a fully working work-around for 4.2.2?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Mar 2012 10:49:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Trigger-real-time-alert-once/m-p/59945#M814</guid>
      <dc:creator>tommasog</dc:creator>
      <dc:date>2012-03-05T10:49:40Z</dc:date>
    </item>
    <item>
      <title>Re: Trigger real time alert once</title>
      <link>https://community.splunk.com/t5/Alerting/Trigger-real-time-alert-once/m-p/59946#M815</link>
      <description>&lt;P&gt;rpm -Uvh splunk-4.3-115073-linux-2.6-x86_64.rpm&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;There are a few performance and security issues that are solved as well when upgrading.&lt;/P&gt;

&lt;P&gt;/k&lt;/P&gt;</description>
      <pubDate>Mon, 05 Mar 2012 12:40:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Trigger-real-time-alert-once/m-p/59946#M815</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2012-03-05T12:40:14Z</dc:date>
    </item>
    <item>
      <title>Re: Trigger real time alert once</title>
      <link>https://community.splunk.com/t5/Alerting/Trigger-real-time-alert-once/m-p/59947#M816</link>
      <description>&lt;P&gt;Did this ever get resolved? I'm looking for this same thing now, 7 years later... Is this built in?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jul 2018 19:34:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Trigger-real-time-alert-once/m-p/59947#M816</guid>
      <dc:creator>dijikul</dc:creator>
      <dc:date>2018-07-18T19:34:06Z</dc:date>
    </item>
  </channel>
</rss>

