Alerting splunk

New Member

we have Splunk log monitoring alert configured for x occurrences in 5 minutes so in 30 minutes, we get around 6 incidents.
We would like to have a solution to have just one incident until first issue is fixed. Is there any way to achieve

Tags (1)
0 Karma

Re: Alerting splunk


You can supress alerts using the throttle tickbox in the alert configuration:

See screenshot:

See documentation:

View solution in original post

0 Karma