Showing results for 
Search instead for 
Did you mean: 
Create Post
Level 8

How to avoid firing multiple alerts from a rule

I have a rule created to send out an email when an port scan is detected. The rule itself works but I'm having an issue when I'm testing it where it fires off tons of the same alerts. I have the "Set time when a rule won't trigger" enabled (see attached) but I must not be understanding how it works.

0 Kudos
0 Replies