# Suppression of repeated alerts

**URL:** https://discuss.elastic.co/t/suppression-of-repeated-alerts/277365
**Category:** Elastic Security
**Created:** [June 29, 2021, 2:56pm UTC](https://discuss.elastic.co/t/suppression-of-repeated-alerts/277365 "2021-06-29T14:56:32Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![dhiegoalves](https://avatars.discourse-cdn.com/v4/letter/d/53a042/32.png) [@dhiegoalves](https://discuss.elastic.co/u/dhiegoalves)
#### Post date: [June 29, 2021, 2:56pm UTC](https://discuss.elastic.co/t/suppression-of-repeated-alerts/277365/1 "2021-06-29T14:56:32Z")

</div>

Hello guys!

Is it possible to configure a suppression to a SIEM's rule on ELK SIEM module?

For example, if 5 events to the same [user.id](http://user.id/) and source.ip in 5 minuts, so will be trigged just 1 alert.

---

<div class="post-metadata">

### Author: ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)
#### Post date: [July 16, 2021, 6:05pm UTC](https://discuss.elastic.co/t/suppression-of-repeated-alerts/277365/2 "2021-07-16T18:05:04Z")

</div>

Yes, using the threshold rules you should be able to. Have you tried it out yet? You can set your threshold to be `>= 1` with it and then your interval and look-back will help you out with how often it fires.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [August 13, 2021, 6:05pm UTC](https://discuss.elastic.co/t/suppression-of-repeated-alerts/277365/3 "2021-08-13T18:05:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
