How to set up Alert Throttle for multiple hosts?

Path Finder

Hi All,

We are trying to setup CPU alerts for few servers and we are looking to throttle the alerts to reduce the noise.


Option 1: 
Trigger = Once
Throttle = Checked 
Suppress trigger for = 4 hours
If I select this option then suppose there is an issue for one host and alert is triggered. it won't generate another alert for 4 hrs. but I think we are going to miss if there is an issue with another host during that 4 hrs.  is it ?

Option 2:
Trigger = For Each Results
Throttle = Checked 
Suppress results containing field value = host
Suppress trigger for = 4 hours

If we choose this option issue is it there are 10 host it will generate 10 separate alert for each host.  

Can some one guide what will be the better way to setup this alert ?


Labels (4)
0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...