Alerting

How to ignore the duplicate count

ManojPottella
New Member

Hi Team,

As per below output I want to know the exact count of disconnected status of each server_name by ignoring the duplicate counts.

As we are using script from splunk to ingest the server status every 5 min, once slunk triggered an alert with server is disconnected, we are manually starting and it will take 15-20 min, in between 3/4 times script will execute and ingest the server status into splunk .

in this if count the total count if disconnected state by using stats count it will include the duplicate count as well, but we need to identify the exact count.

     Server_Name             Status
server1.example.com         disconnected
server1.example.com         disconnected
server1.example.com         connected
server1.example.com         connected
server1.example.com         connected
server1.example.com         disconnected
server1.example.com         disconnected
server1.example.com         connected
server1.example.com         connected
server1.example.com         connected
server2.example.com         disconnected
server2.example.com         disconnected
server2.example.com         disconnected
server2.example.com         disconnected
server2.example.com         disconnected
server2.example.com         connected
server2.example.com         connected
server2.example.com         disconnected
server2.example.com         disconnected
server2.example.com         connected
server3.example.com         connected
server3.example.com         disconnected
server3.example.com         disconnected
server3.example.com         disconnected
server3.example.com         connected
server3.example.com         disconnected
server3.example.com         disconnected
server3.example.com         disconnected
server3.example.com         connected
server3.example.com         connected
server3.example.com         disconnected

server3.example.com disconnected
server3.example.com disconnected
server3.example.com connected

as per above result we are expecting disconnected count of each server is

server1.example.com - disconnected - count=2
server2.example.com - disconnected - count=2
server3.example.com - disconnected - count=3

any logic , please suggest ...

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Ignoring events that have already been alerted is a built-in feature of Splunk. Use the 'throttling' settings in your alert. Tell it to throttle alerts for 15 minutes based on the Server_Name field.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...