# Detection rules that only alert on the 1st detection of an event

**URL:** <https://discuss.elastic.co/t/detection-rules-that-only-alert-on-the-1st-detection-of-an-event/290933>\
**Category:** Elastic Security\
**Tags:** detection-rules\
**Created:** [December 3, 2021, 9:30pm UTC](https://discuss.elastic.co/t/detection-rules-that-only-alert-on-the-1st-detection-of-an-event/290933 "2021-12-03T21:30:16Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![kossde](https://avatars.discourse-cdn.com/v4/letter/k/f19dbf/32.png) [@kossde](https://discuss.elastic.co/u/kossde)\
**Post date:** [December 3, 2021, 9:30pm UTC](https://discuss.elastic.co/t/detection-rules-that-only-alert-on-the-1st-detection-of-an-event/290933/1 "2021-12-03T21:30:16Z")

</div>

Apologies, but I am pretty new to the detection rules process. So any help is greatly appreciated!

I was wondering if anyone knew of a way that I could create a detection rule that only alerts the first time an event occurs within a specified timeframe? We need to see the 1st instance of an event but not be notified of every (if any) event that occurs afterwards within a set timeframe.

I realize that I can create actions that only happen once every hour, etc, but I specifically need this to only happen every 3 hours.

Also, is there a way to create a query that alerts only when the number of events is LESS than a specified number? Think Threshold detections but reversed: If such and such event occurs exactly 1 time within the last 5 minutes, perform action. Otherwise, don't.

---

<div class="post-metadata">

**Author:** ![jamesspi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamesspi/32/24479_2.png) [@jamesspi](https://discuss.elastic.co/u/jamesspi)\
**Post date:** [December 7, 2021, 3:48pm UTC](https://discuss.elastic.co/t/detection-rules-that-only-alert-on-the-1st-detection-of-an-event/290933/2 "2021-12-07T15:48:21Z")

</div>

Hey @kossde,

Unfortunately, both these asks aren't possible right now within the detection engine itself.

That being said - for the second question, you may want to look into transforms. Transforms will allow you to pre-aggregate data into a new index. You can then just use a traditional KQL query on the new index like `event.count < x`.

> **[Tutorial: Transforming the eCommerce sample data | Elasticsearch Guide \[7.15\]...](https://www.elastic.co/guide/en/elasticsearch/reference/current/ecommerce-transforms.html)**

Let me know if you had any other questions on the topic.

James

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 4, 2022, 3:49pm UTC](https://discuss.elastic.co/t/detection-rules-that-only-alert-on-the-1st-detection-of-an-event/290933/3 "2022-01-04T15:49:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
