# Reducing the number of Alerts

**URL:** <https://discuss.elastic.co/t/reducing-the-number-of-alerts/42022>\
**Category:** Logstash\
**Created:** [February 17, 2016, 12:01pm UTC](https://discuss.elastic.co/t/reducing-the-number-of-alerts/42022 "2016-02-17T12:01:38Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![praveen\_siem](https://avatars.discourse-cdn.com/v4/letter/p/e9a140/32.png) [@praveen\_siem](https://discuss.elastic.co/u/praveen_siem)\
**Post date:** [February 17, 2016, 12:01pm UTC](https://discuss.elastic.co/t/reducing-the-number-of-alerts/42022/1 "2016-02-17T12:01:38Z")

</div>

We are creating rule "Brute force Attack" in ELK with the condition as mentioned below:

if "Invalid" in [tags] {  
throttle {  
before\_count =\> 5  
after\_count =\> 5  
period =\> 86400  
key =\> "%{src\_ip}"  
add\_tag =\> "throttled"  
}  
}

what does the parameter "period=\>86400" indicate here, it is that if there are 5 events from the same source IP, the rule will not trigger for the next 24 hours

OR

if 5 events occur in a time frame of 2 mins, the rule will trigger.

Which one holds true.? We are looking for second one...with no repititions in the next 24 hours.

Thanks  
/Praveen

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 18, 2016, 6:27am UTC](https://discuss.elastic.co/t/reducing-the-number-of-alerts/42022/2 "2016-02-18T06:27:47Z")

</div>

> **[throttle | Logstash Reference \[2.1\] | Elastic](https://www.elastic.co/guide/en/logstash/2.1/plugins-filters-throttle.html)**

> As long as the count is less than the before\_count or greater than the after\_count, the event will be "throttled" which means the filter will be considered successful and any tags or fields will be added.

Period being the time that it looks for the events, so it's the first one.

---

<div class="post-metadata">

**Author:** ![praveen\_siem](https://avatars.discourse-cdn.com/v4/letter/p/e9a140/32.png) [@praveen\_siem](https://discuss.elastic.co/u/praveen_siem)\
**Post date:** [February 18, 2016, 7:03am UTC](https://discuss.elastic.co/t/reducing-the-number-of-alerts/42022/3 "2016-02-18T07:03:56Z")

</div>

Thanks Mark,

Consider, the second case - "if 5 events occur in a time frame of 2 mins, the rule will trigger", how do you write the condition for this case in ELK.

Thanks  
/Praveen

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:10am UTC](https://discuss.elastic.co/t/reducing-the-number-of-alerts/42022/4 "2017-07-06T05:10:56Z")

</div>


