How does Panther handle alert deduplication if rules share the same dedup string and dedup period?


If I have two different analysis rules that produce the same dedup string value and this happens within a DedupPeriodMinutes, will this result in only one alert being generated or two separate alerts?


Two separate but identical rules that share the same dedup string value, within the same dedup period, will produce two separate alerts. 

The deduplication functionality corresponds to each separate rule. 

