<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Throttle not working as intended in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Throttle-not-working-as-intended/m-p/456673#M8100</link>
    <description>&lt;P&gt;It still triggered and by switching that box to once you can't throttle on specific fields.&lt;/P&gt;</description>
    <pubDate>Mon, 19 Aug 2019 19:27:09 GMT</pubDate>
    <dc:creator>Hegemon76</dc:creator>
    <dc:date>2019-08-19T19:27:09Z</dc:date>
    <item>
      <title>Throttle not working as intended</title>
      <link>https://community.splunk.com/t5/Alerting/Throttle-not-working-as-intended/m-p/456670#M8097</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have not utilized throttling before and wanted to try it out on an event I know is happening all the time. The purpose of doing this is I have another alert I want to make for when a host is infected 10 times within a 24 hour period of time and want to make sure I'm doing it correctly because that alert probably (hopefully) will never fire.&lt;/P&gt;

&lt;P&gt;product=windows name"An account was successfully logged on" user=Administrator earliest=-1h | transaction Workstation_Name | search eventcount &amp;gt;10 | table Workstation_Name, user&lt;/P&gt;

&lt;P&gt;I have this alert scheduled for every hour at 45 on the hour and to fire when the number of results is greater than 0 on every result. I clicked throttle and suppressed the Workstation_Name field for &lt;STRONG&gt;2 hours&lt;/STRONG&gt; but the alert fires &lt;STRONG&gt;every hour&lt;/STRONG&gt; still? This seems straight forward but I'm obviously doing something wrong. Mind you this event fires around 4 thousand times an hour.&lt;/P&gt;

&lt;P&gt;As I am writing this the only thing I foresee being an issue outside of getting the actual throttle to work is defining the time within a specific days 24 hour period of time. 00:00:00 to 23:59:59. Will I need to do that within the search itself if so how?&lt;/P&gt;

&lt;P&gt;Thank you for the help.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:49:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Throttle-not-working-as-intended/m-p/456670#M8097</guid>
      <dc:creator>Hegemon76</dc:creator>
      <dc:date>2020-09-30T01:49:48Z</dc:date>
    </item>
    <item>
      <title>Re: Throttle not working as intended</title>
      <link>https://community.splunk.com/t5/Alerting/Throttle-not-working-as-intended/m-p/456671#M8098</link>
      <description>&lt;P&gt;hmm try this and see&lt;/P&gt;

&lt;P&gt;scroll down to 'Action Options' sections (which has throttle checkbox), and change the "When triggered, execute actions" from 'For each result' to 'Once'.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2019 19:02:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Throttle-not-working-as-intended/m-p/456671#M8098</guid>
      <dc:creator>Sukisen1981</dc:creator>
      <dc:date>2019-08-19T19:02:40Z</dc:date>
    </item>
    <item>
      <title>Re: Throttle not working as intended</title>
      <link>https://community.splunk.com/t5/Alerting/Throttle-not-working-as-intended/m-p/456672#M8099</link>
      <description>&lt;P&gt;I'm wondering though if I set it to once.&lt;/P&gt;

&lt;P&gt;Lets says workstations A, B and C all get infections within 24 hours. Does it fire per station or just fire once and then stop because the condition was met?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2019 19:05:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Throttle-not-working-as-intended/m-p/456672#M8099</guid>
      <dc:creator>Hegemon76</dc:creator>
      <dc:date>2019-08-19T19:05:51Z</dc:date>
    </item>
    <item>
      <title>Re: Throttle not working as intended</title>
      <link>https://community.splunk.com/t5/Alerting/Throttle-not-working-as-intended/m-p/456673#M8100</link>
      <description>&lt;P&gt;It still triggered and by switching that box to once you can't throttle on specific fields.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2019 19:27:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Throttle-not-working-as-intended/m-p/456673#M8100</guid>
      <dc:creator>Hegemon76</dc:creator>
      <dc:date>2019-08-19T19:27:09Z</dc:date>
    </item>
  </channel>
</rss>

