Yes and I am currently suppressing these flood events. Unfortunately though, sometimes it can be very late by the time the flood events can be suppressed and they may already have taken up a good chunk of your daily license limit, if they haven't already tripped it. I am hoping if Splunk/some Splunk-app can auto-learn/recognize the flood storm and temporarily suppress these events and alert the admin, so they can take a look. In short, a a built-in flood protection.
... View more