Hi,
i got a problem with high frequency in time frame window alert. example :
- firewall alert with 2000x denied trafic in 5 minutes. i use profiler to create the alert, all the event after alert trigered wich match for each condition became an alert became an alert.
How i handle this kind of alert with metron?
Thanks.