<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Email Alerting error in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Email-Alerting-error/m-p/76870#M1059</link>
    <description>&lt;P&gt;Hi, I'm having error with the alerts sent by email since I upgraded to Splunk 5.&lt;BR /&gt;
I have a real time alert search but Im getting this alert sent to my email all day with the same event and I think its something I did wrong in the configuration.&lt;BR /&gt;
I attach the alert configuration, thanks in advanced.&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://dl.dropbox.com/u/97076067/df.png" alt="alt text" /&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 03 Jan 2013 16:19:29 GMT</pubDate>
    <dc:creator>christinmb</dc:creator>
    <dc:date>2013-01-03T16:19:29Z</dc:date>
    <item>
      <title>Email Alerting error</title>
      <link>https://community.splunk.com/t5/Alerting/Email-Alerting-error/m-p/76870#M1059</link>
      <description>&lt;P&gt;Hi, I'm having error with the alerts sent by email since I upgraded to Splunk 5.&lt;BR /&gt;
I have a real time alert search but Im getting this alert sent to my email all day with the same event and I think its something I did wrong in the configuration.&lt;BR /&gt;
I attach the alert configuration, thanks in advanced.&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://dl.dropbox.com/u/97076067/df.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jan 2013 16:19:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Email-Alerting-error/m-p/76870#M1059</guid>
      <dc:creator>christinmb</dc:creator>
      <dc:date>2013-01-03T16:19:29Z</dc:date>
    </item>
    <item>
      <title>Re: Email Alerting error</title>
      <link>https://community.splunk.com/t5/Alerting/Email-Alerting-error/m-p/76871#M1060</link>
      <description>&lt;P&gt;This depends on the window in which the real-time search is run. For example lets assume a window of 30 min and the throttling you have configured (10 min). Now lets say the search has two results (seen at time 0), Splunk sends an email and keeps quiet for 10 min.&lt;/P&gt;

&lt;P&gt;Now after 10 min the throttling is turned off and still these two events are seen since the window rolls over 30 min, this time at time 10. Thus another email is send and so on.&lt;/P&gt;

&lt;P&gt;Solutions to this can be to decrease or increase the real-time window (once again I don't know your setting since it is not shown in the screenshot), to adjust the condition (ie. number of events greater than 10 instead of 1) or to adjust the throttling time to match the real-time window.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jan 2013 13:41:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Email-Alerting-error/m-p/76871#M1060</guid>
      <dc:creator>qjvtenkroode</dc:creator>
      <dc:date>2013-01-08T13:41:55Z</dc:date>
    </item>
    <item>
      <title>Re: Email Alerting error</title>
      <link>https://community.splunk.com/t5/Alerting/Email-Alerting-error/m-p/76872#M1061</link>
      <description>&lt;P&gt;The time range i have is:&lt;BR /&gt;
    # start time: rt&lt;BR /&gt;
    # finish time: rt&lt;/P&gt;

&lt;P&gt;Alert mode is in "once per results" with the same alert condition showed in the screen shot&lt;/P&gt;

&lt;P&gt;And I disabled the Throttling option&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jan 2013 16:47:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Email-Alerting-error/m-p/76872#M1061</guid>
      <dc:creator>christinmb</dc:creator>
      <dc:date>2013-01-08T16:47:45Z</dc:date>
    </item>
    <item>
      <title>Re: Email Alerting error</title>
      <link>https://community.splunk.com/t5/Alerting/Email-Alerting-error/m-p/76873#M1062</link>
      <description>&lt;P&gt;Well by setting the search to rt, rt and the alert mode to "once per result" you will be alerted for every event after one event is found. (ie. the second, the third, the fourth and so on).&lt;/P&gt;

&lt;P&gt;It really depends on what you're trying to achieve.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jan 2013 16:57:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Email-Alerting-error/m-p/76873#M1062</guid>
      <dc:creator>qjvtenkroode</dc:creator>
      <dc:date>2013-01-08T16:57:37Z</dc:date>
    </item>
  </channel>
</rss>

