The idea is to run the search every 60 min and look back 60 min, every 4 hrs and look back 4 hrs, ect... If a high risk object is found during 60 min I would want a notable event to be created but for it not to generate a notable event when the search runs across 4, 8 and 24 hrs. However the search should create a new notable event if risk score increases again by 100 points in 60 min.
Example: userX accumulates a risk score of 150 between 10am-11am on Monday and a notable event is created. Since a notable has been created I would not want a new notable to fire when the search runs for 4,8, and 24hrs. However if the same user, userX accumulates another 125 pts of risk between 1pm-2pm I would want another Notable Event to be created.
I tried using a subsearch against the notable index but could not find a way to pass the risk_object through.
... View more