Alerts have throttles but that's at the alert level, not at the event which have been looked at. As I said, it depends on your search and your data. For example, if you are searching over 25 hours, ...
See more...
Alerts have throttles but that's at the alert level, not at the event which have been looked at. As I said, it depends on your search and your data. For example, if you are searching over 25 hours, every 24 hours, there will be an overlap of 1 hour. Having said that, it depends how quickly your data is indexed, real lag, and how far behind your timestamp field (_time) is to actual time, extended lag. In order to fashion a search which takes these factors into account, you need to understand your data, how it is indexed, when it is indexed, etc. When you know this, you might have a chance at eliminating events which you have (or may have) already looked at. Another way you might approach this is to copy the events you have looked at into a summary index and then ignore any events which are already in your summary index.