Within the “Advanced Options” of the “About Rule” section of Elastic hides a useful feature that gets little attention.This feature makes the rule generate alerts that are ‘hidden’ from the alerts view.Create threshold rules to identify interesting behaviors when 5 or more of them occur within a time period.Build new terms rules to look for the first time someone performs a 'low' behavior, based on existing threshold rules.