<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alert throttling resets in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Alert-throttling-resets/m-p/559485#M10639</link>
    <description>&lt;P&gt;So&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/74999"&gt;@jwelch_splunk&lt;/a&gt;&amp;nbsp;I was looking at&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Alerting/Alert-suppression-List-throttled-suppressed-field-values/m-p/521262" target="_blank"&gt;https://community.splunk.com/t5/Alerting/Alert-suppression-List-throttled-suppressed-field-values/m-p/521262&lt;/A&gt;&amp;nbsp;Thanks for the info on&amp;nbsp;&lt;SPAN&gt;/opt/splunk/var/run/splunk/scheduler/suppression/ as it appears that it may be related to my issue.&lt;BR /&gt;&lt;BR /&gt;Are you aware if this file gets modified when you deploy a new app or change a saved search?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 14 Jul 2021 18:56:16 GMT</pubDate>
    <dc:creator>cyberbilliam</dc:creator>
    <dc:date>2021-07-14T18:56:16Z</dc:date>
    <item>
      <title>Alert throttling resets</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-throttling-resets/m-p/559458#M10638</link>
      <description>&lt;P&gt;So we have a search creating a notable event.&amp;nbsp; The search is configured to suppress for 2 days.&amp;nbsp; The search is managed in an a Splunk app.&amp;nbsp; If we install a new version of the app, or make any changes to the search, the throttle appears to be reset.&lt;/P&gt;&lt;P&gt;My question is if it is possible to preserve the throttling&amp;nbsp; between app installs or changes to the search?&amp;nbsp; Ultimately what we want to avoid is changes to the app causing duplicate notable events from being created.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 16:26:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-throttling-resets/m-p/559458#M10638</guid>
      <dc:creator>cyberbilliam</dc:creator>
      <dc:date>2021-07-14T16:26:26Z</dc:date>
    </item>
    <item>
      <title>Re: Alert throttling resets</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-throttling-resets/m-p/559485#M10639</link>
      <description>&lt;P&gt;So&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/74999"&gt;@jwelch_splunk&lt;/a&gt;&amp;nbsp;I was looking at&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Alerting/Alert-suppression-List-throttled-suppressed-field-values/m-p/521262" target="_blank"&gt;https://community.splunk.com/t5/Alerting/Alert-suppression-List-throttled-suppressed-field-values/m-p/521262&lt;/A&gt;&amp;nbsp;Thanks for the info on&amp;nbsp;&lt;SPAN&gt;/opt/splunk/var/run/splunk/scheduler/suppression/ as it appears that it may be related to my issue.&lt;BR /&gt;&lt;BR /&gt;Are you aware if this file gets modified when you deploy a new app or change a saved search?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 18:56:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-throttling-resets/m-p/559485#M10639</guid>
      <dc:creator>cyberbilliam</dc:creator>
      <dc:date>2021-07-14T18:56:16Z</dc:date>
    </item>
  </channel>
</rss>

