Hello
I need some assistance please with the alert throttle functionality in splunk
Even though we have the alert throttle enabled & suppressed for 60mins the alert still seems to generate a trigger every 10mins @ 00:10, 00:20, 00:30, 00:40, and 00:50
I only want the 00:10 event to trigger & then suppress the 00:20, 00:30, 00:40 & 00:50 events.
Thank you in advance
Veeru
Just setup throttling.
@woodcock
I did it but it is not suppressing the alerts
My answer was a passive-aggressive prod. You need to ADD DETAIL. Show us the entry in savedsearches.conf.