Skip to content

Reduce TI alert noise #2815

Description

@JocLRojas

Describe the feature

Reduce redundant ThreatWinds feed alerts by collapsing matching IP, domain, and host indicators on each event side into one alert, selecting the highest feed level and breaking ties by IP, Domain, then Host.

Use Case

A single event side can match multiple feed indicators and produce redundant alerts. Collapsing those hits and grouping related detections reduces alert volume.

Proposed Solution

No response

Other Information

No response

Acknowledgements

  • I may be able to implement this feature request
  • This feature might incur a breaking change

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions