Find the noise on /signals
Open /signals. Look for repeated rows that share a `correlation_key` — the dashboard shows the key in the row detail. The matcher keys on this exact correlation_key, so a rule covers every future event with the same key.
Common patterns: same source IP + same disposition (TP-SCAN repeated 30 times), same user_agent + same endpoint (a probe pattern).
You can identify at least 3 rows that share a correlation_key.