# 1 alert for all detections & suppress repeat detections

**URL:** <https://discuss.elastic.co/t/1-alert-for-all-detections-suppress-repeat-detections/251550>\
**Category:** Elastic Security\
**Created:** [October 9, 2020, 9:55am UTC](https://discuss.elastic.co/t/1-alert-for-all-detections-suppress-repeat-detections/251550 "2020-10-09T09:55:27Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![probson](https://avatars.discourse-cdn.com/v4/letter/p/e47c2d/32.png) [@probson](https://discuss.elastic.co/u/probson)\
**Post date:** [October 9, 2020, 9:55am UTC](https://discuss.elastic.co/t/1-alert-for-all-detections-suppress-repeat-detections/251550/1 "2020-10-09T09:55:27Z")

</div>

Hi,

I am now on 7.9.2, is there the ability to create an alert for all detections or does it involve going through each indivudually? Also i remember there was talk of been able to suppress detections so that noisy detections do not spam alerts, is this part of Actions Frequency?

At the moment i am using elastalert to do the above but looking to move to the elastic cloud and would like to mimic the control we currently have.

Thanks  
Phil

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [October 9, 2020, 12:35pm UTC](https://discuss.elastic.co/t/1-alert-for-all-detections-suppress-repeat-detections/251550/2 "2020-10-09T12:35:03Z")

</div>

> is there the ability to create an alert for all detections or does it involve going through each indivudually?

Not at the moment, no.

> Also i remember there was talk of been able to suppress detections so that noisy detections do not spam alerts, is this part of Actions Frequency?

We have frequency you can set:

 ![Screen Shot 2020-10-09 at 6.33.39 AM](https://us1.discourse-cdn.com/elastic/original/3X/8/2/8239f62776ebfd0facfaf8d89d8b333d81df2fdb.jpeg)

And if you have false positives you can add exceptions to a rule here:

 ![Screen Shot 2020-10-09 at 6.31.56 AM](https://us1.discourse-cdn.com/elastic/original/3X/d/6/d6a0de6babb0e29dcf5fa93af697648e9e007a46.png)

---

<div class="post-metadata">

**Author:** ![probson](https://avatars.discourse-cdn.com/v4/letter/p/e47c2d/32.png) [@probson](https://discuss.elastic.co/u/probson)\
**Post date:** [October 9, 2020, 1:48pm UTC](https://discuss.elastic.co/t/1-alert-for-all-detections-suppress-repeat-detections/251550/3 "2020-10-09T13:48:38Z")

</div>

@Frank_Hassanabad

So does hourly mean that a detection that is triggered multiple times for a host.name will be alerted once then every hour if it persists, if another device for the same detection triggers within that hour will it then alert and start an hourly period for that device, or is it per detection and if multiple devices/hosts trigger you will receive the one alert for the first and once every hour if it persists.

Regarding the 1 alert for multiple rules, is that on the roadmap?

I have used the exclusions, very handy. Much easier than having to butcher the query.

Thanks  
Phil

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [October 12, 2020, 2:10pm UTC](https://discuss.elastic.co/t/1-alert-for-all-detections-suppress-repeat-detections/251550/4 "2020-10-12T14:10:19Z")

</div>

> Regarding the 1 alert for multiple rules, is that on the roadmap?

Hard to say as we have a lot of overlap of features and things change quickly. For example a lot of people request a way to "bulk edit rules" which could be used to solve your use case.

If you want you're always free to request a feature:

> **[Build software better, together](https://github.com/elastic/kibana/issues/new?template=Feature_request.md)**
>
> GitHub is where people build software. More than 100 million people use GitHub to discover, fork, and contribute to over 420 million projects.

And then follow the ticket to see what happens.

Here are the docs for the actions and when they fire:

> **[Managing signal detection rules | SIEM Guide \[7.8\] | Elastic](https://www.elastic.co/guide/en/siem/guide/current/rules-ui-create.html)**

 ![Screen Shot 2020-10-12 at 8.04.06 AM](https://us1.discourse-cdn.com/elastic/original/3X/6/1/61ca2d77ddac49bb2bc08ec42c186d195a519520.png)

It should fire when there are signals for that particular rule during the hour, daily, weekly, etc... for that rule. So if you select daily, it should only fire once daily if there are 1 or more signals for that particular rule during that day.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:15am UTC](https://discuss.elastic.co/t/1-alert-for-all-detections-suppress-repeat-detections/251550/5 "2022-11-04T08:15:03Z")

</div>


