<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How does throttling work with real-time searches? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-does-throttling-work-with-real-time-searches/m-p/445279#M7819</link>
    <description>&lt;P&gt;Ok, but does it apply to my case? -&lt;/P&gt;

&lt;P&gt;We have an &lt;STRONG&gt;All time (real time)&lt;/STRONG&gt; alert which produced 315 alerts in the first eight hours of the day.&lt;BR /&gt;
When running the search query of the alert for these eight hours, we get &lt;STRONG&gt;six events&lt;/STRONG&gt;.&lt;/P&gt;

&lt;P&gt;We have barely &lt;STRONG&gt;six events&lt;/STRONG&gt; that satisfy the criteria. &lt;/P&gt;</description>
    <pubDate>Tue, 13 Aug 2019 14:30:54 GMT</pubDate>
    <dc:creator>danielbb</dc:creator>
    <dc:date>2019-08-13T14:30:54Z</dc:date>
    <item>
      <title>How does throttling work with real-time searches?</title>
      <link>https://community.splunk.com/t5/Alerting/How-does-throttling-work-with-real-time-searches/m-p/445275#M7815</link>
      <description>&lt;P&gt;In &lt;A href="https://answers.splunk.com/answers/764758/why-are-we-getting-excessive-number-of-alerts.html"&gt;Why are we getting excessive number of alerts?&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;We have an &lt;STRONG&gt;All time (real time)&lt;/STRONG&gt; alert which produced 315 alerts in the first eight hours of the day.&lt;BR /&gt;
When running the search query of the alert for these eight hours, we get &lt;STRONG&gt;six events&lt;/STRONG&gt;.&lt;/P&gt;

&lt;P&gt;I hear that throttling can solve the issue. How would it work?&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2019 14:05:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-does-throttling-work-with-real-time-searches/m-p/445275#M7815</guid>
      <dc:creator>danielbb</dc:creator>
      <dc:date>2019-08-13T14:05:35Z</dc:date>
    </item>
    <item>
      <title>Re: How does throttling work with real-time searches?</title>
      <link>https://community.splunk.com/t5/Alerting/How-does-throttling-work-with-real-time-searches/m-p/445276#M7816</link>
      <description>&lt;P&gt;Hi @danielbb &lt;BR /&gt;
Have a look at this answer by @linu1988  and try these changes to throttle alert as per required suppress time.&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/409031/why-does-my-real-time-alert-continue-to-send-email.html"&gt;https://answers.splunk.com/answers/409031/why-does-my-real-time-alert-continue-to-send-email.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2019 14:21:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-does-throttling-work-with-real-time-searches/m-p/445276#M7816</guid>
      <dc:creator>493669</dc:creator>
      <dc:date>2019-08-13T14:21:11Z</dc:date>
    </item>
    <item>
      <title>Re: How does throttling work with real-time searches?</title>
      <link>https://community.splunk.com/t5/Alerting/How-does-throttling-work-with-real-time-searches/m-p/445277#M7817</link>
      <description>&lt;P&gt;Throttling will allow you to not keep sending the same alert every time it runs.  So if you are sending an alert when some value exceeds a threshold as an example.  If you run the alert every 5 minutes, it will alert, every time that value is over that threshold.  By throttling, you can have Splunk only alert every x amount of time, such as every hour.  This means say for the same host, you will only get an alert every hour if the condition still exists in an hour.  Rather than every time the alert runs.  You can set the time period, and the fields that need to match before it throttles.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2019 14:25:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-does-throttling-work-with-real-time-searches/m-p/445277#M7817</guid>
      <dc:creator>kmorris_splunk</dc:creator>
      <dc:date>2019-08-13T14:25:46Z</dc:date>
    </item>
    <item>
      <title>Re: How does throttling work with real-time searches?</title>
      <link>https://community.splunk.com/t5/Alerting/How-does-throttling-work-with-real-time-searches/m-p/445278#M7818</link>
      <description>&lt;P&gt;Look please at the scenarios from &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.0/Alert/ThrottleAlerts"&gt;Throttle configuration and scenarios&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/7498iD14592D17FADCB26/image-size/large?v=v2&amp;amp;px=999" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;As far as I understand, &lt;STRONG&gt;throttling&lt;/STRONG&gt; is the process of consolidating multiple events into one alert, which isn't my case.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2019 14:27:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-does-throttling-work-with-real-time-searches/m-p/445278#M7818</guid>
      <dc:creator>danielbb</dc:creator>
      <dc:date>2019-08-13T14:27:07Z</dc:date>
    </item>
    <item>
      <title>Re: How does throttling work with real-time searches?</title>
      <link>https://community.splunk.com/t5/Alerting/How-does-throttling-work-with-real-time-searches/m-p/445279#M7819</link>
      <description>&lt;P&gt;Ok, but does it apply to my case? -&lt;/P&gt;

&lt;P&gt;We have an &lt;STRONG&gt;All time (real time)&lt;/STRONG&gt; alert which produced 315 alerts in the first eight hours of the day.&lt;BR /&gt;
When running the search query of the alert for these eight hours, we get &lt;STRONG&gt;six events&lt;/STRONG&gt;.&lt;/P&gt;

&lt;P&gt;We have barely &lt;STRONG&gt;six events&lt;/STRONG&gt; that satisfy the criteria. &lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2019 14:30:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-does-throttling-work-with-real-time-searches/m-p/445279#M7819</guid>
      <dc:creator>danielbb</dc:creator>
      <dc:date>2019-08-13T14:30:54Z</dc:date>
    </item>
  </channel>
</rss>

