A correlation search for wastewater firewall denies is flooding notables because one noisy historian produces hundreds of matching rows. What should be configured on the search so adaptive responses do not fire on every row?
Select an answer to reveal the explanation.
Short Explanation
One chatty historian can look like a war if every deny becomes a notable. Trigger conditions are the gate: fire the action after N results or unique dests, not on row one. That is how ES searches stay house-trained.
Full Explanation
Correlation searches in Enterprise Security include trigger conditions that decide when adaptive responses run, such as number of results or a count of unique field values. Bounding the trigger prevents a single noisy civic host from creating a flood of notables or risk events. Removing the asset from Asset and Identity, unscheduling the search, or hiding the whole queue are the wrong levers. Analysts should request trigger conditions when creating or tuning ES searches.