I wanted to send email to certain people automatically whenever there is high spikes on CPU Load/Memory on specific server. But I am getting email every 5 minutes which has set the time in Alert trigger option. Splunk is simply executing the query(Set the time to search the data every 3 minutes) which I have written and sending email on every 5 min of interval.
Please help me on this.
the savedsearches.conf have quite few options, which can restrict/control this.
Can you please paste copy of your stanza from savedsearches.conf with the parameters used