Action Options

The fields for Action Options are as follows:

  • When triggered, execute actions: Once or For each result. For example, should the alert trigger for each error that mary receives or once for all errors within a time range?
  • Throttle?: You can use throttling (usually based on time and/or event count) to reduce the frequency at which an alert triggers, since an alert can trigger frequently based on similar results that the search returns or the schedule to run the alert.

Get Implementing Splunk 7 - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.