If the same event comes in within a certain period of time, only the first event can trigger the policy and raise an alert. Subsequent alerts can be suppressed.
You can activate and configure Duplicate Suppression in the alert policy on the “Conditions” tab under “Duplicate Suppression Activated”.
If you click on “Exceptions” you can define the time period from seconds to hours and the parameters that will be used for duplicate detection.
You can check the parameters that need to change in order to prevent Duplicate Suppression. In the above example new events will not be suppressed if “Computer Domain” or “Computer ID” change for new incoming events.