Event Threshold
The Event Record of a security or network incident that is based on one or more logs, and on a customizable set of rules that are defined in the Event Policy. Threshold allows you to modify the limits that, when exceeded, indicate that an event occurred. Limits include the number of logs, and the timeframe in which they occurred:
Detect the event when more than X logs were detected over a period of Y seconds.
To decrease the number of false alarms based on a particular event, increase the number of logs and/or the timeframe for them to occur.