Alerting

How to throttle Splunk alert configuration?

Veeru
Path Finder

Hello 

I need some assistance please with the alert throttle functionality in splunk

 

Even though we have the  alert throttle enabled & suppressed for 60mins the alert still seems to generate a trigger every 10mins  @ 00:10, 00:20, 00:30, 00:40, and 00:50

I only want the 00:10 event to trigger & then suppress the 00:20, 00:30, 00:40 & 00:50 events.

 

Thank you in advance
Veeru

Labels (2)
Tags (1)
0 Karma

woodcock
Esteemed Legend

Just setup throttling.

0 Karma

Veeru
Path Finder

@woodcock 
I did it but it is not suppressing the alerts

0 Karma

woodcock
Esteemed Legend

My answer was a passive-aggressive prod.  You need to ADD DETAIL.  Show us the entry in savedsearches.conf.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...