Skip to content
Discussion options

You must be logged in to vote

After further testing, as suggested, I found two working solutions:

  1. Adjusting flow timeout:
    Changing the flow-timeout: established value from 300 to 1 causes alerts from continuous pings to appear approximately every 2 minutes in the SOC dashboard. This behavior can likely be tuned further.

  2. Using flow:stateless in the detection source of the rule:
    Adding flow:stateless makes each ping trigger a separate alert, which then appears consistently. The alert rate can then be controlled using thresholds.

Both approches work, I'll consider the issue resolved.
Thanks again for the support

Replies: 2 comments 5 replies

Comment options

You must be logged in to vote
5 replies
@Trylyo
Comment options

@Trylyo
Comment options

@cm-ops
Comment options

@Trylyo
Comment options

Answer selected by Trylyo
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants