I need to alert on a threshold. I would like to create an alert that looks at a source IP address and will alert me if that address attempts to connect to a threshold of devices over 445. So if Comp1 makes connection to more than 50 devices over 445 within 5 mins, please alert me. Or something like that... Numbers are only for illustration.
Thanks.
Please can you provide some anonymised sample events so we can see what it is you are working with? Please include the fields you already have extracted.