Alerting

Should the list of fields be separated by a space or comma in the per result throttling text box for alerts?

kbecker
Communicator

When setting up throttling in a alert the Per result throttling field text box doesn't indicate if your list of fields should be separated by a space or comma, does anybody know the correct syntax?

Thanks,

ChrisG
Splunk Employee
Splunk Employee

It is a comma-delimited field list. See alert.suppress.fields in savedsearches.conf. We have updated the topic in the Alerting Manual to include this information.

Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...