Skip to content

Frequency rule with realert using number as field type in query key returns wrong number of match #1490

Closed Locked Answered by oTwoWin
oTwoWin asked this question in Q&A
Discussion options

You must be logged in to vote

Hello !

After testing a few other scenarios, I finally found out what it was rather an issue of comprehension.

I didn't fully understand the query_key logic in this scenario.

In this case, I wanted to detect a source making multiple attempts and then silence based on both fields. But not multiple attempts by source IP AND signature.

It wasn't behaving as it was logically thought in the first place so that's why the confusion about it. But it works with numeric field type.

If someone steps into this, you may want to check thoroughly the documentation !

Best regards,

Daniel

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by oTwoWin
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
1 participant