Look for a solution to limit number of positives for an alert to 24 hours. Right now I have an alert for site to site VPNs down but it is alerting me about disconnects from greater than 5 minutes. As you can image that would return all vpn disconnects for as long as the machine has been up. So I want to limit it to the last 24 hours.
Is that possible? Below is the alert rule: syslog.timestamp >= “macros.past_5m” AND syslog.msg REGEXP “ASA-4-113019” AND syslog.msg REGEXP “LAN-to-LAN” AND syslog.msg NOT REGEXP “User Requested” AND syslog.msg NOT REGEXP “Idle Timeout”