Helix may disable a rule you created to ensure performance and stability. There are three circumstances that can result in your rule being throttled:
Your rule matches on too many events per second. If you receive this error, you can:
Refine the rule’s query so that fewer events are likely to match.
Your rule generated too many unique results. If you receive this error, you can:
Refine the rule’s query so that fewer events are likely to match.
Consider removing one field from the groupby parameter, if your rule uses more than one.
If the time window is greater than one minute, remove the window altogether.
Your rule generated too many alerts within a window of time. This error is most often seen when a rule creates ten or more alerts in less than one second. If you receive this error, you can:
Refine the rule's query so that fewer events are likely to match.
Consider removing one field from the groupby parameter, if your rule uses more than one.