New to Splunk
I have a search
They have it set up to email them.
When you are looking at search, you see tons of results ... but no email is ever sent.
then number of results
greater then 3
in 1 minute
throttle every 120 seconds
they want to get a email every time there are more then X number of data entries
It is possible that email notification settings still need to be configured. This should be done before email alert notifications can be sent. You can find more details here:
Based on your trigger conditions, it is also not clear if the number of results that occur in one minute is enough to cause the alert to trigger.
For more details, see
Hope this helps!