Apologies, but I am pretty new to the detection rules process. So any help is greatly appreciated!
I was wondering if anyone knew of a way that I could create a detection rule that only alerts the first time an event occurs within a specified timeframe? We need to see the 1st instance of an event but not be notified of every (if any) event that occurs afterwards within a set timeframe.
I realize that I can create actions that only happen once every hour, etc, but I specifically need this to only happen every 3 hours.
Also, is there a way to create a query that alerts only when the number of events is LESS than a specified number? Think Threshold detections but reversed: If such and such event occurs exactly 1 time within the last 5 minutes, perform action. Otherwise, don't.