Hi,
With existing alert actions you wont be able to achieve this. Also here I can see you need to implement custom throttling logic. I think the best way here is to create custom alert actions. There basically you can write this whole logic in python including the custom throttling logic.
you can refer the below links for custom alert action,
https://docs.splunk.com/Documentation/Splunk/7.3.1/AdvancedDev/ModAlertsIntro
I also created some contents on custom alert action, you can refer them too,
https://youtu.be/UqJAc7rpFmQ
https://youtu.be/ZvzTowF9v9I
https://youtu.be/OT11XMB8Bu0
Sid
... View more