Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

What is a threshold alert?

A threshold alert is generated when a configured count or measurement reaches a set limit within defined conditions. It establishes that the platform counted enough qualifying data, not that the activity was malicious.

Counting logic shapes the result

Rules may count failed logins, connections, messages, file changes or data volume over a fixed or rolling window. They may group by account, device or address, reset after alerting, and suppress repeat notifications.

Duplicate events, delayed batches and several sources contributing to one group can change the count. Collection gaps can make it lower than reality. The same volume might indicate password testing, backup, deployment or normal business use.

Reconstruct what crossed the line

Preserve the rule version, threshold, window, group fields, exclusions and underlying events. Establish why the limit was chosen and compare the activity with a relevant normal baseline.

Report that the configured threshold was reached, including what was counted. Any conclusion about attack, intent or impact should come from the event pattern and corroborating evidence rather than the number alone.

The point to remember

A threshold alert proves a configured count was reached; counting method and context explain its significance.

Reference: LOG-105Logs, Records & Provider Evidence