I have a rule that I've got set up to set different severity levels based on match count. 1-10 is low, 10-100 is medium, 101+ is high. I've uploaded the image from the console that shows this:
Since this was set up, I've noticed that the severity will always be set to High for incidents matching this rule. Let's say I'm looking at an incident with 1 match, I will go into the history and see the severity set twice after detection, first it will be set to low, then to high.
Under history, I'll see the events:
1: Detected
2: Severity Changed : Low
3: Severity Changed : High
When I go change the default level, entry 3 will be whatever I set the default severity to. Is there a way to remove the default severity level? Or a way to make it so that it only sets the severity once?