<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configured real-time issue alert and got multiple mails for single error in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Configured-real-time-issue-alert-and-got-multiple-mails-for/m-p/376166#M94643</link>
    <description>&lt;P&gt;Hi @jodyfsu,&lt;/P&gt;

&lt;P&gt;Thanks for you help. I wanted that kind of configuration. Now it's working fine.&lt;/P&gt;

&lt;P&gt;But now I'm stuck in it's next step.&lt;/P&gt;

&lt;P&gt;Whenever Splunk found any error, it's create a report in pdf format and send a mail notification.&lt;/P&gt;

&lt;P&gt;So, suppose today I got four error alerts on different time. So in the first mail contain the first error with pdf but from the second mail alert I got the first error+the new error(second alert) , then in the third mail alert in the pdf I got first error+second error+new error(third error). It made more complicated to understand what is actually real time error, just because it contains previous errors. &lt;/P&gt;

&lt;P&gt;My Real -time alert settings :&lt;/P&gt;

&lt;P&gt;Alert Type : Real-Time&lt;/P&gt;

&lt;P&gt;Trigger Conditions: &lt;BR /&gt;
     Trigger alert when : Per-Result&lt;BR /&gt;
     Throttle : Checked&lt;BR /&gt;
     Suppress results containing field value : *&lt;BR /&gt;
     Suppress triggering for : 24 hour(s)&lt;/P&gt;

&lt;P&gt;Please help me on this matter.&lt;BR /&gt;
If you have any links for this issue, please attach the link.&lt;/P&gt;

&lt;P&gt;Thanks, @saibal6&lt;/P&gt;</description>
    <pubDate>Mon, 11 Jun 2018 13:53:50 GMT</pubDate>
    <dc:creator>saibal6</dc:creator>
    <dc:date>2018-06-11T13:53:50Z</dc:date>
    <item>
      <title>Configured real-time issue alert and got multiple mails for single error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configured-real-time-issue-alert-and-got-multiple-mails-for/m-p/376164#M94641</link>
      <description>&lt;P&gt;I have configured an alert notification on real-time issue and it's working. But I have facing a problem, that any new issue is appear wherever it has only single line error. I got multiple mail notification where the mail time differences was only for 4 seconds means I got 12mails in just one minute for the same single line error. &lt;/P&gt;

&lt;P&gt;Where I want only single mail notification on single line real time error.&lt;BR /&gt;
can anyone suggest/help me on this matter? &lt;/P&gt;</description>
      <pubDate>Thu, 07 Jun 2018 11:15:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configured-real-time-issue-alert-and-got-multiple-mails-for/m-p/376164#M94641</guid>
      <dc:creator>saibal6</dc:creator>
      <dc:date>2018-06-07T11:15:54Z</dc:date>
    </item>
    <item>
      <title>Re: Configured real-time issue alert and got multiple mails for single error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configured-real-time-issue-alert-and-got-multiple-mails-for/m-p/376165#M94642</link>
      <description>&lt;P&gt;When you configure the Alert you can select "Throttle" and then you can say how long to not notify you.&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="Throttle"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5177i5EC666CB19459B4D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Throttle" alt="Throttle" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Hope this helps. Let us know if you need more.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jun 2018 13:49:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configured-real-time-issue-alert-and-got-multiple-mails-for/m-p/376165#M94642</guid>
      <dc:creator>jodyfsu</dc:creator>
      <dc:date>2018-06-07T13:49:36Z</dc:date>
    </item>
    <item>
      <title>Re: Configured real-time issue alert and got multiple mails for single error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configured-real-time-issue-alert-and-got-multiple-mails-for/m-p/376166#M94643</link>
      <description>&lt;P&gt;Hi @jodyfsu,&lt;/P&gt;

&lt;P&gt;Thanks for you help. I wanted that kind of configuration. Now it's working fine.&lt;/P&gt;

&lt;P&gt;But now I'm stuck in it's next step.&lt;/P&gt;

&lt;P&gt;Whenever Splunk found any error, it's create a report in pdf format and send a mail notification.&lt;/P&gt;

&lt;P&gt;So, suppose today I got four error alerts on different time. So in the first mail contain the first error with pdf but from the second mail alert I got the first error+the new error(second alert) , then in the third mail alert in the pdf I got first error+second error+new error(third error). It made more complicated to understand what is actually real time error, just because it contains previous errors. &lt;/P&gt;

&lt;P&gt;My Real -time alert settings :&lt;/P&gt;

&lt;P&gt;Alert Type : Real-Time&lt;/P&gt;

&lt;P&gt;Trigger Conditions: &lt;BR /&gt;
     Trigger alert when : Per-Result&lt;BR /&gt;
     Throttle : Checked&lt;BR /&gt;
     Suppress results containing field value : *&lt;BR /&gt;
     Suppress triggering for : 24 hour(s)&lt;/P&gt;

&lt;P&gt;Please help me on this matter.&lt;BR /&gt;
If you have any links for this issue, please attach the link.&lt;/P&gt;

&lt;P&gt;Thanks, @saibal6&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2018 13:53:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configured-real-time-issue-alert-and-got-multiple-mails-for/m-p/376166#M94643</guid>
      <dc:creator>saibal6</dc:creator>
      <dc:date>2018-06-11T13:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: Configured real-time issue alert and got multiple mails for single error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configured-real-time-issue-alert-and-got-multiple-mails-for/m-p/376167#M94644</link>
      <description>&lt;P&gt;Ah, I would change the search time to be only last 60 minutes or few hours. Like you are seeing, since you are looking back 24 hours it is going to return any other alerts triggered in the last 24 hours. &lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2018 14:00:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configured-real-time-issue-alert-and-got-multiple-mails-for/m-p/376167#M94644</guid>
      <dc:creator>jodyfsu</dc:creator>
      <dc:date>2018-06-11T14:00:50Z</dc:date>
    </item>
  </channel>
</rss>

