Knowing what you don't know

We had an incident yesterday where a hardware device changed it's password, but failed to sync. As such there was 937 messages in 3 minutes but no rules fired because we did not have a generic catch all to notify us that something was wrong.

I propose that a generic catch all rule be available that states something to the effect if the same message appears more than X times ever Y seconds to send out a notification.

This will also help with tuning the device.

