Hello,
I'd like to understand if it's possible with any Splunk version, preferably version 6 or later, to implement this type of behavior:
- Send and email only the first time the alarm condition is met. If the alarm (scheduled with the "cron" method) triggers again the next time, don't send any email
- Send an "end of alarm" email, after an alarm fired, when the alarm condition is not met anymore
Thanks.