2020-02-19 05:28 AM
Hi,
For the ESA Rule is there an option not to create additional notifications for certain time post first notification. For example lets take an alert logic where the requirement is to alert multiple failed login attempted by User A for 5 times in 2 minutes where in I could create rule logic but could not restrict in such a way that once alert has triggered alert for same user should not be triggered for say next 6 hours.
Any suggestions is much appreciated.
Regards,
Varun P G
2020-02-19 05:39 AM
Please use OUTPUT FIRST EVERY 6 hours; syntax in Rule for supressing duplicate alerts for 6 hours.
2020-02-19 07:42 AM
Hi Sravan,
Would there be any performance issue which I should think about on the time window?
Regards,
Varun P G
2020-02-20 12:37 AM
Hi Varun Govindaraj,
This will not impact performance of ESA. But, advances to avoid duplicate alerting.