I notice that the rule includes an AnyAlert.ToolAlias. Since all the other correlation fields are ServiceWarning, why not set this to ServiceWarning.ToolAlias? The AnyAlert would cause a lot of memory utilization and might be causing false positives on the rule.
↧