# Optimize Action in Alerts to trigger only once for a detected anomaly

**URL:** <https://discuss.elastic.co/t/optimize-action-in-alerts-to-trigger-only-once-for-a-detected-anomaly/152008>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [October 11, 2018, 8:21am UTC](https://discuss.elastic.co/t/optimize-action-in-alerts-to-trigger-only-once-for-a-detected-anomaly/152008 "2018-10-11T08:21:22Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![andres-perez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andres-perez/32/136461_2.png) [@andres-perez](https://discuss.elastic.co/u/andres-perez)\
**Post date:** [October 11, 2018, 9:25am UTC](https://discuss.elastic.co/t/optimize-action-in-alerts-to-trigger-only-once-for-a-detected-anomaly/152008/2 "2018-10-11T09:25:26Z")

</div>

You can set a [throttle\_period](https://www.elastic.co/guide/en/x-pack/current/actions.html#actions-ack-throttle) long enough to ensure that the anomalies are resolved.

If the current anomaly (i.e. what makes the `condition` come true) is resolved within the throttle period:

- the next watch execution won't have it's `condition` met so...
- no `actions` will be executed and
- the alert will be "rearmed", ready for the next anomaly.

A similar question has been asked here recently, you can get more information there: [How to stop sending duplicate Slack notifications for the same error?](https://discuss.elastic.co/t/how-to-stop-sending-duplicate-slack-notifications-for-the-same-error/151460?u=andres-perez)

---

_[View the full topic](https://discuss.elastic.co/t/optimize-action-in-alerts-to-trigger-only-once-for-a-detected-anomaly/152008)._
