I have a set of error events that are generated when an issue happens in our environment. I run an alert every day to see if there are any events over the previous day and send a table of the results to an administrator.
The problem now is that the administrator has got annoyed with Splunk sending similar events every day and wants to set an event to be "Acknowledged" for a certain amount of time (7 days). If the error occurs again in those 7 days, we do not want to get an email, but we do want to get an email if a different issue occurs.
So... What I have done is to set up a [status] lookup with the following field definition: