how to get alert when any asset generate thousands of events in minute


Today we have received more than 20k of events from particular asset within 30 min but we are unable to receive alarm, what policies we need to configure to detect the same. The internal asset performing quality analysis ,so it hits only the port 80 and  risk showing totally 0 in alienvault USM

Please suggest what is the problem of not getting alarm 

    hi Igor, that´s for one specific but that´s should be in general


