This is a similar case and maybe useful for you.
https://answers.splunk.com/answers/53161/alert-when-a-host-exceeds-a-certain-number-of-messages-per-minute.html
... View more
Hello,
Splunk has a built in alert that you can use. From your search head, go to settings, searches, reports and alerts.
filter the type, app and user by ALL.
you should see a list of predefined alerts.
This may be of interest to you:
DMC Alert - Total License Usage Near Daily Quota
Regards,
Maureen
... View more