# Optimize Action in Alerts to trigger only once for a detected anomaly

**URL:** <https://discuss.elastic.co/t/optimize-action-in-alerts-to-trigger-only-once-for-a-detected-anomaly/152008>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [October 11, 2018, 8:21am UTC](https://discuss.elastic.co/t/optimize-action-in-alerts-to-trigger-only-once-for-a-detected-anomaly/152008 "2018-10-11T08:21:22Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Elango-mas](https://avatars.discourse-cdn.com/v4/letter/e/779978/32.png) [@Elango-mas](https://discuss.elastic.co/u/Elango-mas)\
**Post date:** [October 11, 2018, 8:21am UTC](https://discuss.elastic.co/t/optimize-action-in-alerts-to-trigger-only-once-for-a-detected-anomaly/152008/1 "2018-10-11T08:21:22Z")

</div>

Hi Experts,

I need to optimize the alerts as triggered in scheduled interval in which the action is to be executed only once for detected anomalies and the same alert should not execute the action until the anomaly is resolved and execute the action again if the same anomaly is detected again.

can you help me in creating the alert as above statement?

Thanks in advance

- Elango

---

<div class="post-metadata">

**Author:** ![andres-perez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andres-perez/32/136461_2.png) [@andres-perez](https://discuss.elastic.co/u/andres-perez)\
**Post date:** [October 11, 2018, 9:25am UTC](https://discuss.elastic.co/t/optimize-action-in-alerts-to-trigger-only-once-for-a-detected-anomaly/152008/2 "2018-10-11T09:25:26Z")

</div>

You can set a [throttle\_period](https://www.elastic.co/guide/en/x-pack/current/actions.html#actions-ack-throttle) long enough to ensure that the anomalies are resolved.

If the current anomaly (i.e. what makes the `condition` come true) is resolved within the throttle period:

- the next watch execution won't have it's `condition` met so...
- no `actions` will be executed and
- the alert will be "rearmed", ready for the next anomaly.

A similar question has been asked here recently, you can get more information there: [How to stop sending duplicate Slack notifications for the same error?](https://discuss.elastic.co/t/how-to-stop-sending-duplicate-slack-notifications-for-the-same-error/151460?u=andres-perez)

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 15, 2018, 7:15am UTC](https://discuss.elastic.co/t/optimize-action-in-alerts-to-trigger-only-once-for-a-detected-anomaly/152008/3 "2018-10-15T07:15:17Z")

</div>

throttle period is one possible solution to this - but it might be limited.

If you really need to check for previous executions, a chain input, where the first input consists of querying the last three watch history entries for this watch might be helpful. This way you could detect also flapping of your check, if you need to.

Hope this helps!

--Alex

---

<div class="post-metadata">

**Author:** ![Elango-mas](https://avatars.discourse-cdn.com/v4/letter/e/779978/32.png) [@Elango-mas](https://discuss.elastic.co/u/Elango-mas)\
**Post date:** [October 15, 2018, 12:23pm UTC](https://discuss.elastic.co/t/optimize-action-in-alerts-to-trigger-only-once-for-a-detected-anomaly/152008/4 "2018-10-15T12:23:37Z")

</div>

Thank you @andres-perez and @spinscale for the suggestions I am try to work this out.

Will update once I am done

🙂 Elango MAS

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 12, 2018, 12:38pm UTC](https://discuss.elastic.co/t/optimize-action-in-alerts-to-trigger-only-once-for-a-detected-anomaly/152008/5 "2018-11-12T12:38:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
