Alerting

How to throttle Splunk alert configuration?

Veeru
Path Finder

Hello 

I need some assistance please with the alert throttle functionality in splunk

 

Even though we have the  alert throttle enabled & suppressed for 60mins the alert still seems to generate a trigger every 10mins  @ 00:10, 00:20, 00:30, 00:40, and 00:50

I only want the 00:10 event to trigger & then suppress the 00:20, 00:30, 00:40 & 00:50 events.

 

Thank you in advance
Veeru

Labels (2)
Tags (1)
0 Karma

woodcock
Esteemed Legend

Just setup throttling.

0 Karma

Veeru
Path Finder

@woodcock 
I did it but it is not suppressing the alerts

0 Karma

woodcock
Esteemed Legend

My answer was a passive-aggressive prod.  You need to ADD DETAIL.  Show us the entry in savedsearches.conf.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...