- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Seeing duplicated alerts each time the alerts triggers
Klas_splunk7777
Observer
08-21-2020
08:54 AM
We have only one log in the Splunk, but the user is receiving 2 alerts at a time with the same search id.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
alonsocaio
Contributor
08-21-2020
10:04 AM
Hi,
Which trigger conditions are you using? Have you enabled throttle for this alert?
If for any reason search is returning duplicate results you would enable throttle based on an unique field for that event.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Klas_splunk7777
Observer
08-24-2020
08:23 AM
Basically, this alert is looking for an event so I mentioned fields command at the end, and the throttle is not enabled..
Example:
| fields field1 field2
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
isoutamo

SplunkTrust
08-24-2020
08:32 AM
Can you post this alert from savedsearches.conf or screen shot from GUI. Those helps the Community to help you.
r. Ismo
