<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk alert to ignore user for a week in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Splunk-alert-to-ignore-user-for-a-week/m-p/555137#M10572</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;your alert need to return all users by it’s own row if they are alerted. Then in alert dialog select alert per results and needed throttle time for that.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.0/Alert/AlertTriggerConditions" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.0/Alert/AlertTriggerConditions&lt;/A&gt;&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
    <pubDate>Wed, 09 Jun 2021 16:48:22 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2021-06-09T16:48:22Z</dc:date>
    <item>
      <title>Splunk alert to ignore user for a week</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-alert-to-ignore-user-for-a-week/m-p/555135#M10571</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;I am working on a unique request and was wondering if its possible.&lt;/P&gt;&lt;P&gt;The request is to run an alert every hour and if a user appears in the alert, it should ignore the same user for one week.&lt;/P&gt;&lt;P&gt;Need your help if it can be configured.&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jun 2021 16:37:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-alert-to-ignore-user-for-a-week/m-p/555135#M10571</guid>
      <dc:creator>spodda01da</dc:creator>
      <dc:date>2021-06-09T16:37:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk alert to ignore user for a week</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-alert-to-ignore-user-for-a-week/m-p/555137#M10572</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;your alert need to return all users by it’s own row if they are alerted. Then in alert dialog select alert per results and needed throttle time for that.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.0/Alert/AlertTriggerConditions" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.0/Alert/AlertTriggerConditions&lt;/A&gt;&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jun 2021 16:48:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-alert-to-ignore-user-for-a-week/m-p/555137#M10572</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-06-09T16:48:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk alert to ignore user for a week</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-alert-to-ignore-user-for-a-week/m-p/555842#M10592</link>
      <description>&lt;P&gt;Thanks for the response, I am going to test it further.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 17:59:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-alert-to-ignore-user-for-a-week/m-p/555842#M10592</guid>
      <dc:creator>spodda01da</dc:creator>
      <dc:date>2021-06-15T17:59:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk alert to ignore user for a week</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-alert-to-ignore-user-for-a-week/m-p/555905#M10596</link>
      <description>&lt;P&gt;In Alerts for Splunk Admins, &lt;A href="https://splunkbase.splunk.com/app/3796/" target="_blank"&gt;https://splunkbase.splunk.com/app/3796/&lt;/A&gt; or &lt;A href="https://github.com/gjanders/SplunkAdmins" target="_blank"&gt;https://github.com/gjanders/SplunkAdmins&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I have examples such as SearchHeadLevel - Users exceeding the disk quota introspection, &amp;nbsp;where I use a lookup file to stop emailing users for a week. A separate report cleans up the lookup&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's another alternative...&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jun 2021 04:59:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-alert-to-ignore-user-for-a-week/m-p/555905#M10596</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2021-06-16T04:59:16Z</dc:date>
    </item>
  </channel>
</rss>

