# Auto ack alert possible?

**URL:** <https://discuss.elastic.co/t/auto-ack-alert-possible/58989>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [August 25, 2016, 11:25pm UTC](https://discuss.elastic.co/t/auto-ack-alert-possible/58989 "2016-08-25T23:25:39Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![obudiman](https://avatars.discourse-cdn.com/v4/letter/o/e19adc/32.png) [@obudiman](https://discuss.elastic.co/u/obudiman)\
**Post date:** [August 25, 2016, 11:25pm UTC](https://discuss.elastic.co/t/auto-ack-alert-possible/58989/1 "2016-08-25T23:25:39Z")

</div>

Is it possible to have the watch action acknowledged as soon as it has been executed?

Fancy the idea that we will only receive one alert as long as the alert condition is still the same, and only to receive the next one if the alert condition is met after it has returned to normal before.

It seems it is possible to run a webhook action and then have it to run the API via logstash, but just wondering if there's any native way to do this within watcher itself.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 26, 2016, 10:24am UTC](https://discuss.elastic.co/t/auto-ack-alert-possible/58989/2 "2016-08-26T10:24:44Z")

</div>

Hmm, that might be a little to Skynet, don't you think?

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [August 26, 2016, 11:42am UTC](https://discuss.elastic.co/t/auto-ack-alert-possible/58989/3 "2016-08-26T11:42:26Z")

</div>

I think the feature you're looking for is called throttling, which you can define as `throttle_period` at the top-level of the watch, or within an individual action:

[https://www.elastic.co/guide/en/watcher/current/actions.html#actions-ack-throttle](https://www.elastic.co/guide/en/watcher/current/actions.html#actions-ack-throttle)

That seems like it will probably work for you?

---

<div class="post-metadata">

**Author:** ![obudiman](https://avatars.discourse-cdn.com/v4/letter/o/e19adc/32.png) [@obudiman](https://discuss.elastic.co/u/obudiman)\
**Post date:** [August 28, 2016, 11:52pm UTC](https://discuss.elastic.co/t/auto-ack-alert-possible/58989/4 "2016-08-28T23:52:59Z")

</div>

Hm yeah, the throttle will do I suppose. We'll still get multiple alerts for the same incident but at least we can control how often we will get it..

Thanks for the suggestion!

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 5, 2016, 3:46pm UTC](https://discuss.elastic.co/t/auto-ack-alert-possible/58989/5 "2016-09-05T15:46:31Z")

</div>

Hey,

one part on our roadmap is to have a history of earlier watch executions available in the context, so you could use this in a scripted condition. We are still hashing it out, but this might help you in the future!

--Alex

---

<div class="post-metadata">

**Author:** ![obudiman](https://avatars.discourse-cdn.com/v4/letter/o/e19adc/32.png) [@obudiman](https://discuss.elastic.co/u/obudiman)\
**Post date:** [September 6, 2016, 4:21am UTC](https://discuss.elastic.co/t/auto-ack-alert-possible/58989/6 "2016-09-06T04:21:00Z")

</div>

That would be good indeed, thanks for letting us know.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:43pm UTC](https://discuss.elastic.co/t/auto-ack-alert-possible/58989/7 "2017-07-06T13:43:05Z")

</div>


