07-07-2006 07:26 AM - edited 03-10-2019 03:05 AM
let's say I have signature with the following characteristics:
Event Counter
-------------
Event Count: 1
Event Count Key: Attacker and Victim addresses
Specifiy Alert Interval: No
Alert Frequency
---------------
Summary Mode: Fire Once
Summary Key: attacker and victim addresses
Specify Global Summary Threshold: No
Obviously, it will alarm for the first event, but what about subsequent events? Testing reveals that it does eventually generate more alarms...but how much time much pass?
07-09-2006 12:35 AM
The amount of time is indicated by the Summary Interval (Time in seconds used in each summary alert).
I think by default, signatures are set to 15 seconds.
07-10-2006 07:53 AM
AFAICT, there is no summary interval for the "fire once" summary mode. It is not exposed to the user for viewing/modification anyway. 15 seconds doesn't seem likely given the testing I did. It was ~2 minutes that a new alarm would fire.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide