HI all,
I have this rule:
"Unapproved Port Activity Detected" - I know this rule creates many alerts, how can i find the daily count of this specific event? and what is trigger?
You can find details in index=notable
to find number of notables triggered for that correlation rule use below query.
index=notable source=*Unapproved Port Activity Detected*
| timechart span=1d count