Other Usage

Alert Throttle Not Working

griffins
Explorer

Hi folks,

I have a very simple alert set up that triggers if the number of results is greater than 0. I'd like to throttle the alert from triggering again for a specified time period, but the throttle seems to be ignored.

Search:
index=sample host=example_host

Schedule:
Cron - */5 * * * *

Trigger:
Number of Results > 0
Trigger Once

Throttle:
Suppress triggering for 10 minutes.

Action:
Send email.

The alert triggers with no problem; however, rather than throttling for 10 minutes, the alert gets triggered again after 5 minutes if the condition is met. It's a simple search where the trigger condition is there being any results at all. What am I doing wrong here? Any help would be greatly appreciated!

Labels (4)
0 Karma

Thulasinathan_M
Contributor

Your schedluer runs every 5 mins, it should be Cron - */10 * * * *. If you wish to run every 10 mins.

0 Karma

griffins
Explorer

I don't want it to run every 10 minutes, I want the search to run every 5 minutes, but throttle for 10 minutes if the alert condition is met, and an alert is triggered.

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...