Hi,
Is there a way to configure a throttle rule so the splunk forwarder don't send repeated events?
Let's say i want to throttle events so the forwarder only send an event after 10 occurrences, is it possible?
I couldn't find anything about it in the documentation
Thanks
Paula
Hi,
There are no such in-built feature in Splunk but you can write custom script to achieve your requirement and run that script using scripted input at regular interval.
Hi,
There are no such in-built feature in Splunk but you can write custom script to achieve your requirement and run that script using scripted input at regular interval.