SPLK-1002 Macros, Saved Searches and CIM Practice Question
A saved search is configured to run every 5 minutes and send an alert when the count of failures exceeds 10. After several days, users report they are not receiving alerts even though failures are occurring. The saved search runs successfully and produces results. What is the most likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Alert throttling is enabled and suppressing subsequent alerts.
Alert throttling is designed to suppress duplicate alerts within a specified time period. If throttling is enabled, even though the saved search runs every 5 minutes and the condition (count of failures > 10) is met, only the first alert is sent. Subsequent alerts are suppressed until the throttle window resets, explaining why users stop receiving alerts despite ongoing failures. The search runs successfully, so permissions and alert action configuration are not the issue, and the condition is correctly set to exceed 10, not less than 10.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The saved search owner does not have permission to send alerts.
Why it's wrong here
If the search runs, the owner likely has permissions; alert actions require proper role capabilities.
- ✗
The alert action is not configured to send to the intended recipients.
Why it's wrong here
If alerts were working before, this is less likely; but could be, but throttling is more common.
- ✓
Alert throttling is enabled and suppressing subsequent alerts.
Why this is correct
Throttling stops alerts from firing again within a set time window, even if the condition is true again.
- ✗
The alert condition is set to trigger when count is less than 10.
Why it's wrong here
If condition were reversed, it would not trigger when count >10, but question states failures exceed 10.
Go deeper
Related to this question
About these practice questions
This SPLK-1002 question is part of Courseiva's 475-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SPLK-1002 practice question is part of Courseiva's free Splunk certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SPLK-1002 exam.