Throttling applies to any correlation search alert type, including notable events and actions (RSS feed, email, run script, and ticketing).
[Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/EA/ConfigCS, B, C, and D are correct answers because they are the default alert actions that a correlation search can execute besides creating notable events. You can configure a correlation search to send an email, include the results in an RSS feed, or run a custom script when the search matches a defined pattern. Ping a host is not a default alert action for correlation searches. References: Configure correlation search settings in ITSI]
Submit