Alerting

Alert Throttling - where are the throttled values stored?

MKozanic
Path Finder

Hi All,

I'm trying to work out best practice with regards to alert throttling and max time frames.

Trying to determine whether if we where to throttle something for 2 weeks, would we actually be better off filtering in a different way, either by using a lookup or a subsearch.

I'd like to know where the values that are used for throttling are stored, and what whether there is any performance considerations we need to account for when looking at throttling for longer periods.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...