looks like I am missing something.
I have a Splunk alert that is a bit spammy. I would like to use the Alert Manager app to give me one alert a day, basically the first time this alert shows up. And be quiet for the rest of the day, just increase the duplicate counter.
I can get alerts to be counted as duplicates, but I still get e-mails for all of them.
I have not found a way in the suppression rules to hide follow on alerts.