Configure alert thresholds to limit the number of alerts your appliance processes during a hit storm. This setting protects the Endpoint Security (HX) appliance from an overwhelming number of alerts.
Three alert thresholds can be set:
The total alert threshold controls the total number of alert messages that can be processed by the Endpoint Security (HX). See Configuring the total alert threshold
The malware alert threshold controls the number of malware alerts for the same malware infection that can be processed by the Endpoint Security (HX) in a specified interval.
The IOC and exploit alert threshold controls the number of IOC and exploit alerts for the same infection that can be processed by the Endpoint Security (HX) in a specified interval.
Endpoint Detection and Response with Forensics (EDRF) > Manage your workspaces > Configure Forensics workspace > Configure alert thresholds > Configure the total alert threshold
Endpoint Detection and Response with Forensics (EDRF) > Manage your workspaces > Configure Forensics workspace > Configure alert thresholds > Configure the total alert threshold