Alerting

Should the list of fields be separated by a space or comma in the per result throttling text box for alerts?

kbecker
Communicator

When setting up throttling in a alert the Per result throttling field text box doesn't indicate if your list of fields should be separated by a space or comma, does anybody know the correct syntax?

Thanks,

ChrisG
Splunk Employee
Splunk Employee

It is a comma-delimited field list. See alert.suppress.fields in savedsearches.conf. We have updated the topic in the Alerting Manual to include this information.

Get Updates on the Splunk Community!

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...