I currently have the issue that I want to trigger a certain alert, let's call it unusual processes or logins. now, I've created a search - in which I find the specific events that are considered su...
See more...
I currently have the issue that I want to trigger a certain alert, let's call it unusual processes or logins. now, I've created a search - in which I find the specific events that are considered suspicious, and I save it as a sheduled search and as an action I write it into the triggered alerts. the timeframe is -20m@m till -5m@m and the cron job is for every 5 minutes. now I see that there is an issue in that case, because if I cron the job every 5 minutes, given the look back timeframe, I'm getting at least 3 of the same events triggered as an alert. now my question is, is there an option/way to trigger based on whether or not an event already occured ? so basically that the search looks - did I trigger that event before already? if yes, then don't write it in the triggered alerts, otherwise, write it in the triggered alerts. every help is appreciated