I've noticed summary alerts without a preceding non-summarized alert, which I thought was impossible.
Are signatures using a summary mode of "summarize" always supposed to generate 2 alerts, the initial alert that starts the counter and then a summarized alert?
The only explanation I can think of is the event filters. Is it possible that an event filter [especially one with "stop on match" disabled] would prevent the initial alert but not the summarized alert?