<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alert notifications being incorrectly suppressed in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Alert-notifications-being-incorrectly-suppressed/m-p/572165#M13173</link>
    <description>&lt;P&gt;Hi&amp;nbsp;L1mLam,&lt;/P&gt;&lt;P&gt;Just use field name in this option and it will work&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PradReddy_0-1635098289890.png" style="width: 435px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16560i356BC69440649D02/image-dimensions/435x37?v=v2" width="435" height="37" role="button" title="PradReddy_0-1635098289890.png" alt="PradReddy_0-1635098289890.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;More information around alert suppression configuration attributes can be found here -&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.2/Admin/Savedsearchesconf#alert_suppression.2Fseverity.2Fexpiration.2Ftracking.2Fviewing_settings" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.2/Admin/Savedsearchesconf#alert_suppression.2Fseverity.2Fexpiration.2Ftracking.2Fviewing_settings&lt;/A&gt;&lt;/P&gt;&lt;PRE&gt;&lt;BR /&gt;alert.suppress.fields = &amp;lt;comma-delimited-field-list&amp;gt;&lt;BR /&gt;* List of fields to use when suppressing per-result alerts. This field *must*&lt;BR /&gt;be specified if the digest mode is disabled and suppression is enabled.&lt;BR /&gt;* Default: empty string.&lt;/PRE&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;------&lt;/P&gt;&lt;P&gt;An upvote would be appreciated and Accept Solution if it helps!&lt;/P&gt;</description>
    <pubDate>Sun, 24 Oct 2021 18:02:28 GMT</pubDate>
    <dc:creator>PradReddy</dc:creator>
    <dc:date>2021-10-24T18:02:28Z</dc:date>
    <item>
      <title>Alert notifications being incorrectly suppressed</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-notifications-being-incorrectly-suppressed/m-p/570746#M13144</link>
      <description>&lt;P&gt;I have the following results returned by a search query:&lt;/P&gt;&lt;P&gt;_time&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Id1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Id2&lt;BR /&gt;2021-10-13 08:20:22.219&amp;nbsp; &amp;nbsp; &amp;nbsp;ABC471_1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;8456&lt;BR /&gt;2021-10-13 08:20:21.711&amp;nbsp; &amp;nbsp; &amp;nbsp;ABC471_8&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;8463&lt;BR /&gt;2021-10-13 08:20:16.112&amp;nbsp; &amp;nbsp; &amp;nbsp;ABC471_3&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;8458&lt;/P&gt;&lt;P&gt;However, I only receive an alert notification for the first result.&lt;/P&gt;&lt;P&gt;My alert configuration is set up as follows:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;Settings&lt;/STRONG&gt;&lt;BR /&gt;Alert type&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Scheduled&lt;BR /&gt;Time Range&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Today&lt;BR /&gt;Cron Expression&amp;nbsp; &amp;nbsp; &amp;nbsp; */5****&lt;BR /&gt;Expires&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;24 hours&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;Trigger Conditions&lt;/STRONG&gt;&lt;BR /&gt;Number of Results&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;gt;0&lt;BR /&gt;Trigger&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;For each result&lt;BR /&gt;Throttle&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Ticked&lt;BR /&gt;Suppress results&lt;BR /&gt;containing field value&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Id2=$result.Id2$&lt;BR /&gt;Suppress triggering for&amp;nbsp; &amp;nbsp;24 hours&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;Trigger Actions&lt;/STRONG&gt;&lt;BR /&gt;Add to Triggered Alerts&lt;BR /&gt;Send email&lt;/P&gt;&lt;P&gt;I am expecting 3 emails to be generated for each of my search query results given that I am suppressing on Id2 which is different in each case.&amp;nbsp; However, I am just receiving the one alert as stated above.&lt;/P&gt;&lt;P&gt;Can anyone advise me what I am dong wrong in this case?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 13 Oct 2021 12:10:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-notifications-being-incorrectly-suppressed/m-p/570746#M13144</guid>
      <dc:creator>L1mLam</dc:creator>
      <dc:date>2021-10-13T12:10:22Z</dc:date>
    </item>
    <item>
      <title>Re: Alert notifications being incorrectly suppressed</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-notifications-being-incorrectly-suppressed/m-p/572165#M13173</link>
      <description>&lt;P&gt;Hi&amp;nbsp;L1mLam,&lt;/P&gt;&lt;P&gt;Just use field name in this option and it will work&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PradReddy_0-1635098289890.png" style="width: 435px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16560i356BC69440649D02/image-dimensions/435x37?v=v2" width="435" height="37" role="button" title="PradReddy_0-1635098289890.png" alt="PradReddy_0-1635098289890.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;More information around alert suppression configuration attributes can be found here -&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.2/Admin/Savedsearchesconf#alert_suppression.2Fseverity.2Fexpiration.2Ftracking.2Fviewing_settings" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.2/Admin/Savedsearchesconf#alert_suppression.2Fseverity.2Fexpiration.2Ftracking.2Fviewing_settings&lt;/A&gt;&lt;/P&gt;&lt;PRE&gt;&lt;BR /&gt;alert.suppress.fields = &amp;lt;comma-delimited-field-list&amp;gt;&lt;BR /&gt;* List of fields to use when suppressing per-result alerts. This field *must*&lt;BR /&gt;be specified if the digest mode is disabled and suppression is enabled.&lt;BR /&gt;* Default: empty string.&lt;/PRE&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;------&lt;/P&gt;&lt;P&gt;An upvote would be appreciated and Accept Solution if it helps!&lt;/P&gt;</description>
      <pubDate>Sun, 24 Oct 2021 18:02:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-notifications-being-incorrectly-suppressed/m-p/572165#M13173</guid>
      <dc:creator>PradReddy</dc:creator>
      <dc:date>2021-10-24T18:02:28Z</dc:date>
    </item>
  </channel>
</rss>

