Hello everyone,
I'm still very new to the world of Splunk Enterprise. 😉 I hope that you can help me with my problem.
I created the following search to be notified of app updates by email:
The notification type is scheduled to run every day at 12:00 p.m. I chose one as a trigger. However, I get the same ban notification email every day, even though I've already received it.
What do I have to do so that the message is only sent once.
Please excuse my bad English.
Best regards
Björn
Hi @n37w0rk,
you could configure the throttle for your alert, in other words a period, after alert trigger, in which the message isn't sent.
You can configure throttle in alert proprties:
Ciao.
Giuseppe
It can be that easy. I was 100% sure I tested it. Now it's funny. Thanks for the quick help
krgds Björn
Hi @n37w0rk,
good for you, let me know if I can still help you.
If this answer solves your need, please accept it for the other people of Community.
Ciao and happy splunking.
Giuseppe
P.S.: Karma Points are appreciated 😉
Hi @n37w0rk,
you could configure the throttle for your alert, in other words a period, after alert trigger, in which the message isn't sent.
You can configure throttle in alert proprties:
Ciao.
Giuseppe