When setting up throttling in a alert the Per result throttling field text box doesn't indicate if your list of fields should be separated by a space or comma, does anybody know the correct syntax?


Splunk Employee
It is a comma-delimited field list. See alert.suppress.fields in savedsearches.conf. We have updated the topic in the Alerting Manual to include this information.