Store source alert id
kiwiz opened this issue · comments
Would be great if this could be used for deduplication in aggregated searches, or not creating an alert for an already seen log entry.
Currently when searching eg. a 1h time window every couple of minutes, alerts get created as long as results are visible in the sliding window.