I have inherited a medium install of Splunk, and for the most part, I understand everything. But, a simple account locked alert is sending multiple, multiple email notices per minute, and I don't understand why. I'll include a screenshot so anyone who sees something let me know. The purpose is to check for real-time account lockouts and notify only once.
In addition to the great answer from @Vijeta, turn on throttling. This keeps Splunk from generating additional alerts for the same event(s) for a period of time. To do that, click on the "Throttle" box, complete the form, and click Save.