Alerting

Prevent repeat alerts

Branden
Builder

Hi. We have script that Splunk runs every 15 minutes. The script checks to see if a partition is using the primary or back-up ethernet adapter. If it is using the back-up adapter, it notifies us via e-mail.

This alert works great except for one thing: it will repeat the alert every time the script runs. That means we get alerted every 15 minutes, which creates a cluttered mailbox in the morning.

I realize that this may be expected behavior. I'm wondering if anyone has a procedure or trick to prevent a repeat alert from going out.

I'm running Splunk 4.1.5 on the indexer and 4.1.4 on the forwarders.

Thanks!

Tags (2)
1 Solution

ftk
Motivator

Take a look at the AlertThrottle app on Splunkbase, with it you will be able to throttle repeat alerts.

View solution in original post

lmalhoit
Explorer

How did you set it up so that it didn't notify you anymore? I've only been able to throttle it, not stop the notification all together.

0 Karma

ftk
Motivator

Take a look at the AlertThrottle app on Splunkbase, with it you will be able to throttle repeat alerts.

Branden
Builder

🙂
Actually, I went ahead and tried it anyways. I must admit it worked like a charm. Thank you for the tip!

0 Karma

ftk
Motivator

@Branden, the AlertThrottle app was written and is maintained by a Splunk employee. Not sure if that alleviates any reservations, but maybe it will 🙂

0 Karma

Branden
Builder

Thank you for the response. I'm a bit wary about relying on a 3rd party app for our production system (it is poorly documented, has no ratings, and I'm not sure how reliable it is).
Nevertheless, I am willing to give it a try. Unfortunately, I am not sure I can create the custom condition I'm looking for in the custom condition field. I'm sure it can be done, I'll just have to ask it in a separate question.
Thank you again.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...