# Decision to throttle based on a condition

**URL:** <https://discuss.elastic.co/t/decision-to-throttle-based-on-a-condition/149489>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [September 21, 2018, 4:25pm UTC](https://discuss.elastic.co/t/decision-to-throttle-based-on-a-condition/149489 "2018-09-21T16:25:16Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![gautu7](https://avatars.discourse-cdn.com/v4/letter/g/c89c15/32.png) [@gautu7](https://discuss.elastic.co/u/gautu7)\
**Post date:** [September 21, 2018, 4:25pm UTC](https://discuss.elastic.co/t/decision-to-throttle-based-on-a-condition/149489/1 "2018-09-21T16:25:16Z")

</div>

I want to throttle an action based on the result of a previously executed action.  
Let's say I have 10 unique nodes for a fs utilization alert and I want to throttle based on each unique node with the met condition. For example, if Node1 was actioned and alerted the first time, it should be throttled and not actioned and alerted if it appears again within the throttle period.

Is Index Action the ideal way to do this where we store the result of execution and look it up before performing an action?

[https://www.elastic.co/guide/en/x-pack/current/actions-index.html](https://www.elastic.co/guide/en/x-pack/current/actions-index.html)

---

<div class="post-metadata">

**Author:** ![elastock](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elastock/32/35672_2.png) [@elastock](https://discuss.elastic.co/u/elastock)\
**Post date:** [September 24, 2018, 8:58am UTC](https://discuss.elastic.co/t/decision-to-throttle-based-on-a-condition/149489/2 "2018-09-24T08:58:45Z")

</div>

It depend if you have 1 Watch for all nodes , or 1 Watch per nodes.  
I think you should use index action to index properly the results of your watches ,so then , in your watch  
you have to use multiple input :  
-1st input : the query you want to do about the fs utilization  
-2nd input : query the "index-results"

Use [script condition](https://www.elastic.co/guide/en/x-pack/current/condition-script.html) to compare the result of the first input and if the "index-results" contains traces of a recently executed action and then decide what to do ..

---

<div class="post-metadata">

**Author:** ![gautu7](https://avatars.discourse-cdn.com/v4/letter/g/c89c15/32.png) [@gautu7](https://discuss.elastic.co/u/gautu7)\
**Post date:** [October 4, 2018, 7:04pm UTC](https://discuss.elastic.co/t/decision-to-throttle-based-on-a-condition/149489/3 "2018-10-04T19:04:44Z")

</div>

@elastock Thanks, and sorry for being late to the party.  
To your first question, yes, I have a monitoring cluster which houses metrics of 'n' clusters so I have a single watcher which alerts when any node within the 'n' cluster hit the threshold. I have 2 actions, a slack-notification which always triggers and a jira-action which should trigger only once per node per 24 hour interval.  
If I have 2 indexes (monitoring and custom index) to filter on to check if the current node which has met the threshold and this node exists in the custom index before I go ahead and insert into the custom index in the action block, I would not be able to trigger my slack notification. I want both these actions to be kind of independent of each other in the same watch.  
Is this something which can be done or I need to have 2 independent watches with 1 action each?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 1, 2018, 7:04pm UTC](https://discuss.elastic.co/t/decision-to-throttle-based-on-a-condition/149489/4 "2018-11-01T19:04:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
