throttle

verb

In Splunk this usually refers to the practice of alert suppression, usually in relation to an alert that is based on a real-time search. When you have an alert that can be triggered many times in a short amount of time, you can configure it to be throttled such that once the alert is triggered, it can't be triggered again for a stated period of time.

For example, say you set up a real-time alert that, when the conditions are right, can be triggered dozens of times within one or two minutes. Your project stakeholders might find it annoying to get a stack of nearly identical alert emails in quick succession. To mitigate this, you can throttle the alert so that after it is triggered, it can't be triggered again until 10 minutes have passed.

You can set the throttling control when you first create an alert (using the Create Alert dialog box), or when you edit the saved search upon which the alert is based in Manager.

For more information

In the User Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time