I have a simple search:
host=*prod* "Too many open files" source!="/opt/atlassian/jira-data/log/emh.log*"
I've set up a simple alert. Real-time, throttling on host for 1 minute. (pic attached)
We had 200+ of these errors, all within 2 seconds of each other, from a single host 2 hours ago. Since then, we've received no less than 24 emails alerting us of those events. I want one email, not 24.
What have I misconfigured?
Please try to set the below setting with your preferred field. Always try to table to data you require. Moreover the throttling period is only 1 minute, so if you have events matching it will generate the alert. If you want hourly then throttle it to send 1 hour per host in the suppress triggering option.
Thank you. I've made these changes. I've my fingers crossed this will do the trick.