# Threshold confusion (detecting a burst of connections on a specific port)

**URL:** <https://discuss.elastic.co/t/threshold-confusion-detecting-a-burst-of-connections-on-a-specific-port/360246>\
**Category:** Elastic Security\
**Created:** [May 26, 2024, 8:26pm UTC](https://discuss.elastic.co/t/threshold-confusion-detecting-a-burst-of-connections-on-a-specific-port/360246 "2024-05-26T20:26:16Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![beginthread](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/beginthread/32/134817_2.png) [@beginthread](https://discuss.elastic.co/u/beginthread)\
**Post date:** [May 26, 2024, 8:26pm UTC](https://discuss.elastic.co/t/threshold-confusion-detecting-a-burst-of-connections-on-a-specific-port/360246/1 "2024-05-26T20:26:16Z")

</div>

Hi Team!

I am confused about threshold rules types, where I can't really understand the count and cardinality fields.

I want to get an alert when a specific destination.port is frequently used (like a burst). Instead of have an alert everytime a port is used (to many alerts.

I googled a lot and can't find exactly how to work with threshold alerts.

PS : I am using the UI only.

Thanks

---

<div class="post-metadata">

**Author:** ![nikitaindik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikitaindik/32/132780_2.png) [@nikitaindik](https://discuss.elastic.co/u/nikitaindik)\
**Post date:** [May 29, 2024, 12:36pm UTC](https://discuss.elastic.co/t/threshold-confusion-detecting-a-burst-of-connections-on-a-specific-port/360246/2 "2024-05-29T12:36:58Z")

</div>

Hey @beginthread! Welcome to Elastic community!

I am not an expert in detection rules, but I have experimented with rule settings a bit and I think you can do it in one of two ways:

**Option 1**  
Using a Threshold rule. Set " **Group by**" to `destination.port` and " **Threshold**" value to 10. This should only generate an alert if 10 or more events are matched within the rule execution.

As for " **Count**" and " **Unique values**" fields, my understanding is that they work as an additional condition. Let's say you only want an alert if requests to a port come from 3 different machines. Then you would also set "Count" to `source.ip` and "Unique values" to 3.

 ![threshold](https://us1.discourse-cdn.com/elastic/original/3X/2/0/20c6dbeddc7bed14d89a9ebf07fa985ee96786d3.png)

Also, here is the [docs page](https://www.elastic.co/guide/en/security/current/rules-ui-create.html#create-threshold-rule) with a succinct description of the Threshold rule settings.

**Option 2**  
Using a Custom Query rule with alert suppression. Set "Suppress alerts by" to `destination.port`. Then only a single alert will be generated if multiple events are matched during rule execution.

 ![custom_query](https://us1.discourse-cdn.com/elastic/original/3X/8/b/8b5cb289910187aac7687e896361957515f1d766.png)

Hope this helps!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 26, 2024, 12:37pm UTC](https://discuss.elastic.co/t/threshold-confusion-detecting-a-burst-of-connections-on-a-specific-port/360246/3 "2024-06-26T12:37:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
