Timing custom detection rule for multiple Logs

Is it possible for R7 to create a custom alert based of a time limit. Such as, if the are no messages every 15 minutes, then we want this alert to generate for our team. Would appreciate any help.

Hi @mali5,
sure, you can do it directly from the “Detection Rule Library”, by clicking on “Create Detection Rules” at the top right. At the end of the creation wizard you will find the “Add conditions (optional)” section, inside which you can set a threshold. Everything is explained here

I hope I understood your doubt correctly.

see you next time

1 Like