Alerting

Alerting splunk

arunsundaram
New Member

we have Splunk log monitoring alert configured for x occurrences in 5 minutes so in 30 minutes, we get around 6 incidents.
We would like to have a solution to have just one incident until first issue is fixed. Is there any way to achieve

Tags (1)
0 Karma
1 Solution

Azeemering
Builder

You can supress alerts using the throttle tickbox in the alert configuration:

See screenshot:
https://imgur.com/ot9BVzp

See documentation:
https://docs.splunk.com/Documentation/Splunk/7.0.2/Alert/ThrottleAlerts

View solution in original post

0 Karma

Azeemering
Builder

You can supress alerts using the throttle tickbox in the alert configuration:

See screenshot:
https://imgur.com/ot9BVzp

See documentation:
https://docs.splunk.com/Documentation/Splunk/7.0.2/Alert/ThrottleAlerts

0 Karma
Get Updates on the Splunk Community!

Splunk Answers Content Calendar, June Edition II

Get ready to dive into Splunk Dashboard panels this week! We'll be tackling common questions around ...

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...