# How to stop sending duplicate Slack notifications for the same error?

**URL:** <https://discuss.elastic.co/t/how-to-stop-sending-duplicate-slack-notifications-for-the-same-error/151460>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [October 8, 2018, 1:24pm UTC](https://discuss.elastic.co/t/how-to-stop-sending-duplicate-slack-notifications-for-the-same-error/151460 "2018-10-08T13:24:19Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ddregalo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ddregalo/32/32320_2.png) [@ddregalo](https://discuss.elastic.co/u/ddregalo)\
**Post date:** [October 8, 2018, 1:24pm UTC](https://discuss.elastic.co/t/how-to-stop-sending-duplicate-slack-notifications-for-the-same-error/151460/1 "2018-10-08T13:24:20Z")

</div>

I've asked this question in X-Pack +Heartbeat forums with no real progress made - I was referred to @michael.heldebrant for some assistance!?? If you have any insight on this it would be very much appreciated! 🙂

Here's the details...

I have configured a heartbeat watcher to action a slack notification if the monitor status is down in the production environment and this is working fine buuuuuuuut - what I would like to do is NOT send duplicate notifications for the same error. Hence, is it possible to check the condition that triggers the action with the previous result and NOT send if equal??

Here is an example of a watcher:

```auto
{
  "trigger": {
    "schedule": {
      "interval": "1m"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "heartbeat*"
        ],
        "types": [],
        "body": {
          "query": {
            "bool": {
              "must": [
                {
                  "match": {
                    "_index": "heartbeat*"
                  }
                }
              ],
              "filter": [
                {
                  "term": {
                    "monitor.status": "down"
                  }
                },
                {
                  "term": {
                    "fields.environment": "Production"
                  }
                },
                {
                  "range": {
                    "@timestamp": {
                      "gte": "now-5m",
                      "lt": "now"
                    }
                  }
                }
              ]
            }
          },
          "aggs": {
            "unique_hosts": {
              "terms": {
                "field": "monitor.host"
              }
            }
          }
        }
      }
    }
  },
  "condition": {
    "compare": {
      "ctx.payload.hits.total": {
        "gt": 0
      }
    }
  },
  "actions": {
    "notify-slack": {
      "throttle_period_in_millis": 1800000,
      "slack": {
        "message": {
          "to": [
            "#heartbeat-production"
          ],
          "text": "*SUMMARY:* Encountered {{ctx.payload.aggregations.unique_hosts.buckets.size}} unique hosts with status 'down' in the last 5 mins\n*ENVIRONMENT*: {{ctx.payload.hits.hits.0._source.fields.environment}}\n\n*URLs:*\n{{#ctx.payload.aggregations.unique_hosts.buckets}} Host Name: {{key}}\n{{/ctx.payload.aggregations.unique_hosts.buckets}}",
          "icon": "https://image.freepik.com/free-icon/letter-p_318-9235.jpg"
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![andres-perez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andres-perez/32/136461_2.png) [@andres-perez](https://discuss.elastic.co/u/andres-perez)\
**Post date:** [October 8, 2018, 2:46pm UTC](https://discuss.elastic.co/t/how-to-stop-sending-duplicate-slack-notifications-for-the-same-error/151460/2 "2018-10-08T14:46:39Z")

</div>

Can you set a longer [throttle\_period](https://www.elastic.co/guide/en/x-pack/current/actions.html#CO29-1)?  
I see it set to 30 minutes in your example, maybe a bigger value would be enough.

I think it's the most suitable mechanism for handling duplicate notifications.  
Maybe we can suggest to the elastic devs to implement some kind of _"forever"_ value for that parameter 😉

If that were not possible, what comes to my mind would be much more cumbersome:

- Add another search (so _chain inputs_) to obtain the results of the last execution (e.g. sort a small time range) recorded in the _.watcher-history-..._ index each time the watcher is triggered.
- Add comparison logic (so probably a script comparison) to take that values into account.

You can find related information in this question:

> [@Alert when okay](https://discuss.elastic.co/t/alert-when-okay/112707/2):
>
> Hi @acchaulk, Watcher can absolutely do this because it is just a matter of defining a condition to trigger on. If the condition passes, such as when an "error" state is detected, then you can follow up by performing any [action that is supported by Watcher](https://www.elastic.co/guide/en/x-pack/6.1/actions.html). Therefore, the issue that you may be having is how to define the right condition and there are a lot of different strategies that you can employ, depending on the complexity that you are willing to endure: Create two Watches The first W…

---

<div class="post-metadata">

**Author:** ![ddregalo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ddregalo/32/32320_2.png) [@ddregalo](https://discuss.elastic.co/u/ddregalo)\
**Post date:** [October 9, 2018, 7:57am UTC](https://discuss.elastic.co/t/how-to-stop-sending-duplicate-slack-notifications-for-the-same-error/151460/3 "2018-10-09T07:57:28Z")

</div>

Thanks for the response @andres-perez💪 Your first suggestion of a longer throttle period sounds like a reasonable quick fix though I may have a go at your second...a little hacky but if it works would be optimal...cheers! -D

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 6, 2018, 8:03am UTC](https://discuss.elastic.co/t/how-to-stop-sending-duplicate-slack-notifications-for-the-same-error/151460/4 "2018-11-06T08:03:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
