<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to throttle Splunk alert configuration? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-to-throttle-Splunk-alert-configuration/m-p/640015#M14997</link>
    <description>&lt;P&gt;Just setup throttling.&lt;/P&gt;</description>
    <pubDate>Fri, 14 Apr 2023 21:00:54 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2023-04-14T21:00:54Z</dc:date>
    <item>
      <title>How to throttle Splunk alert configuration?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-throttle-Splunk-alert-configuration/m-p/639933#M14994</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I need some assistance please with the alert throttle functionality in splunk&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Even though we have the&amp;nbsp; alert throttle enabled &amp;amp; suppressed for 60mins the alert still seems to generate a trigger every 10mins&amp;nbsp; @ 00:10, 00:20, 00:30, 00:40, and 00:50&lt;/P&gt;
&lt;P&gt;I only want the 00:10 event to trigger &amp;amp; then suppress the 00:20, 00:30, 00:40 &amp;amp; 00:50 events.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you in advance&lt;BR /&gt;Veeru&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2023 16:30:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-throttle-Splunk-alert-configuration/m-p/639933#M14994</guid>
      <dc:creator>Veeru</dc:creator>
      <dc:date>2023-04-14T16:30:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to throttle Splunk alert configuration?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-throttle-Splunk-alert-configuration/m-p/640015#M14997</link>
      <description>&lt;P&gt;Just setup throttling.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2023 21:00:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-throttle-Splunk-alert-configuration/m-p/640015#M14997</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2023-04-14T21:00:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to throttle Splunk alert configuration?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-throttle-Splunk-alert-configuration/m-p/640183#M14998</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/1406"&gt;@woodcock&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;I did it but it is not suppressing the alerts&lt;/P&gt;</description>
      <pubDate>Mon, 17 Apr 2023 09:31:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-throttle-Splunk-alert-configuration/m-p/640183#M14998</guid>
      <dc:creator>Veeru</dc:creator>
      <dc:date>2023-04-17T09:31:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to throttle Splunk alert configuration?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-throttle-Splunk-alert-configuration/m-p/640275#M15002</link>
      <description>&lt;P&gt;My answer was a passive-aggressive prod.&amp;nbsp; You need to ADD DETAIL.&amp;nbsp; Show us the entry in savedsearches.conf.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Apr 2023 18:31:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-throttle-Splunk-alert-configuration/m-p/640275#M15002</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2023-04-17T18:31:23Z</dc:date>
    </item>
  </channel>
</rss>

