‎2012-02-16
07:10 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Correlation Rule_Alert suprresion
Hi All, Can anybody explain how we can use "threshold" and "Alert suppression" in alerting. I am confused between these two features. Thanks
2 Replies
‎2012-02-16
07:36 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Threshold configured within statements tells how many events should match with filter and other conditions configured in the statement/rule before triggering an alert. e.g 10 event in 60 seconds says only trigger an alert if the configure event/s come 10 or more times within 60 seconds. Alert Suppression relates to suppression of the trigger alerts. Many a times it may happen that an alert trigger will keep triggering again and again and usually some time is needed in fixing the issue reported in the triggered alert. So if you configure suppression duplicate alerts for the same rule can be avoided until the time configured in suppression and in the meantime you can fix the issue reported and thus avoid unwanted alerts on the same issue. Hope this helps.
‎2012-02-17
07:52 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Thanks Srijit.
