Hello, I'd like to understand if it's possible with any Splunk version, preferably version 6 or later, to implement this type of behavior: - Send and email only the first time the alarm condition is met. If the alarm (scheduled with the "cron" method) triggers again the next time, don't send any email - Send an "end of alarm" email, after an alarm fired, when the alarm condition is not met anymore Thanks.
... View more