Splunk Search

Stop recurring alerts

sureshchinta
Explorer

I have setup alerts based on a scheduled search in the logs. The application writes a log messages every minute while the error persists, therefore splunk gives out an email per message.

can some one help me with a syntax to avoid reading recurring alerts...

I am clueless in how to approach this problem...ignorance.

Thanks.

Tags (2)
1 Solution

Jeremiah
Motivator

Check out the alert throttle app:

http://blogs.splunk.com/2010/06/01/alert-throttling/

It should help to reduce the number of alerts you receive. You could run your saved search once a minute but only receive notifications once an hour (or whatever interval you like) after the first alert is generated.

View solution in original post

Jeremiah
Motivator

Check out the alert throttle app:

http://blogs.splunk.com/2010/06/01/alert-throttling/

It should help to reduce the number of alerts you receive. You could run your saved search once a minute but only receive notifications once an hour (or whatever interval you like) after the first alert is generated.

Get Updates on the Splunk Community!

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...

Developer Spotlight with Guilhem Marchand

From Splunk Engineer to Founder: The Journey Behind TrackMe    After spending over 12 years working full time ...

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...