Alert counts displayed in Helix Enterprise for an appliance may differ from the corresponding counts displayed in the appliance Web UI or CLI.
These are reasons for the discrepancies:
Network Security IPS events do not generate Helix Enterprise alerts by default.
You could add custom tuning or global exclusions that may suppress some alerts.
Helix Enterprise aggregates similar events into one alert. For example, if Helix Enterprise receives ten Network Security alerts with the same source and destination and threat, they will all be grouped into one alert.
Helix Enterprise has its own aggregation rules and retention policies.