Is it possible to have the Orion Syslog alert email me the "count"?
for example, I have a "Botnet" rule setup so it only triggers if 15 messages are received in 3 minutes. I setup the email with the basic in - host, message, etc. but I wanted to inclue something along the lines of "This message received XX times in XX minutes" - mainly because the content of the message could change. (like the IP address