Implementing Splunk 7(Third Edition)
上QQ阅读APP看书,第一时间看更新

Action Options

The fields for Action Options are as follows:

  • When triggered, execute actions: Once or For each result. For example, should the alert trigger for each error that mary receives or once for all errors within a time range?
  • Throttle?: You can use throttling (usually based on time and/or event count) to reduce the frequency at which an alert triggers, since an alert can trigger frequently based on similar results that the search returns or the schedule to run the alert.