Splunk Enterprise Security

Is throttling based on trigger time? How do we decide?

Woodpecker
Path Finder

Hi,

I have a CS, which runs every 6mins looking back -65m and -5m.. It triggered a notable alert, where for the same dest value, it triggered ten notables in the same time 11.46pm...........................

How much throttle time should I set to avoid this?

Thankyou!

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...