Alerting

How to set up Alert Throttle for multiple hosts?

AKG11
Path Finder

Hi All,

We are trying to setup CPU alerts for few servers and we are looking to throttle the alerts to reduce the noise.

AKG11_1-1671644585967.pngAKG11_1-1671644585967.png

Option 1: 
Trigger = Once
Throttle = Checked 
Suppress trigger for = 4 hours
If I select this option then suppose there is an issue for one host and alert is triggered. it won't generate another alert for 4 hrs. but I think we are going to miss if there is an issue with another host during that 4 hrs.  is it ?

Option 2:
Trigger = For Each Results
Throttle = Checked 
Suppress results containing field value = host
Suppress trigger for = 4 hours

If we choose this option issue is it there are 10 host it will generate 10 separate alert for each host.  

Can some one guide what will be the better way to setup this alert ?

Thanks




Labels (4)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...