Alerting

Throttle alerts based on field value

Path Finder

Is it possible to throttle alerts by field value?

For example: I want to alert when the value of field "action" is "delete" and throttle any subsequent results for 10 minutes unless the value of the field "username" changes.

Tags (2)
0 Karma
1 Solution

Esteemed Legend

Yes, change the Alert mode to Once per result which will enable a field called Per result throttling fields which is where you put username.

View solution in original post

Esteemed Legend

Yes, change the Alert mode to Once per result which will enable a field called Per result throttling fields which is where you put username.

View solution in original post

State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!