Alerting

How to set up Alert Throttle for multiple hosts?

AKG11
Path Finder

Hi All,

We are trying to setup CPU alerts for few servers and we are looking to throttle the alerts to reduce the noise.

AKG11_1-1671644585967.png

Option 1: 
Trigger = Once
Throttle = Checked 
Suppress trigger for = 4 hours
If I select this option then suppose there is an issue for one host and alert is triggered. it won't generate another alert for 4 hrs. but I think we are going to miss if there is an issue with another host during that 4 hrs.  is it ?

Option 2:
Trigger = For Each Results
Throttle = Checked 
Suppress results containing field value = host
Suppress trigger for = 4 hours

If we choose this option issue is it there are 10 host it will generate 10 separate alert for each host.  

Can some one guide what will be the better way to setup this alert ?

Thanks




Labels (4)
0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...