Forum Discussion

Molx32's avatar
Molx32
Brass Contributor
May 29, 2019

[DETECTION] 'Frequency', 'Period', and 'Suppression' precision

Hello,

 

I would like to have more details about the  'Frequency', 'Period', and 'Suppression' parameters. Here is what I understand:

  • Frequency - No problem with this: the query is run every X minute(s) or hour(s);
  • Period - According to the documentation: "control the time window for how much data the query runs on - for example, it can run every hour across 60 minutes of data". This is where I don't understand, since the period is defined within the KQL Query, with TimeGenerated. I must be missing something.
  • Suppression - When an alert rule is triggered for an event E, it will not be triggered again for the next X minute(s) or hour(s), for the same event E. Is that right ?

So, what really is this 'Period' ? I want to be sure to understand each of these parameters.

 

Thank you very much!

 

Clément BONNET

2 Replies

  • GaryBushey's avatar
    GaryBushey
    Bronze Contributor

    Molx32 The Period is used just like its description states, it is the time period for your data.  If you look under the "Set alert query" heading above where you enter your query it does state "Set time and interview parameters only using the Period field under Alert scheduling." 

     

    So it appears that MS does not want any sort of time parameter in the query itself.  Hopefully someone from MS can state why that is.

Resources