I'm creating a number of correlation searches, and I'd like to be able to send an email ONLY when an episode has been open for more then X number of minutes. If i go into the aggregation policy and set 'If this episode existed for X second(s)', then any event that is added to the episode after X seconds triggers an additional email, which potentially could be a lot of emails. I haven't been able to find a combination of settings that will just send an email once from the aggregation policy rules. I considered the option to create an alert search for an episode that has been up for a certain period of time in a 'New' state, but I'd prefer for it to be built into the aggregation policy. Anyone else hit something similar?
... View more