Hi,
The alerting keep sending until the event is resolved, is there any way to configure such that it will alert me 2 times instead of keep alerting me, it is quite irritating to receive the same alert for nonstop. thks
Check these:
http://blogs.splunk.com/2010/06/01/alert-throttling/
http://answers.splunk.com/answers/46099/alert-throttling-whilst-true
The first link should help you to modify your search.