# I can only see the first alert of a rule

**URL:** https://forum.suricata.io/t/i-can-only-see-the-first-alert-of-a-rule/901
**Category:** Help
**Created:** [December 14, 2020, 8:49am UTC](https://forum.suricata.io/t/i-can-only-see-the-first-alert-of-a-rule/901 "2020-12-14T08:49:25Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![Adrian\_Portas](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/adrian_portas/32/517_2.png) [@Adrian\_Portas](https://forum.suricata.io/u/Adrian_Portas)
#### Post date: [December 14, 2020, 8:49am UTC](https://forum.suricata.io/t/i-can-only-see-the-first-alert-of-a-rule/901/1 "2020-12-14T08:49:25Z")

</div>

Hello,

Im new to Suricata and im trying to log a basic icmp alert. My problem its that in fast.log/eve.log i can only see the first alert even if i send an icmp packet every second.

I could “fix” it adding flow: to\_server in the rule but as the flow says only log icmp packets to server. Am i missing something? I tried with threshold too but i couldnt find a solution for my problem.

My rule is:  
alert icmp any any -\> any any (msg:“ICMP detected”; sid: 889;)

The rule that workerd:  
alert icmp any any -\> any any (msg:“ICMP detected”; flow: to\_server; sid: 889;)

In suricata 3.X the alert withouth flow worked well but in suricata 4.X, 5.X and 6.X i have this problem.

Thanks in advance, Adrian

---

<div class="post-metadata">

### Author: ![vjulien](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/vjulien/32/4_2.png) [@vjulien](https://forum.suricata.io/u/vjulien)
#### Post date: [December 14, 2020, 12:19pm UTC](https://forum.suricata.io/t/i-can-only-see-the-first-alert-of-a-rule/901/2 "2020-12-14T12:19:45Z")

</div>

Hi Adrian, I suspect the first rule is considered to be “IP-only”, and so it is evaluated only once per flow direction. Depending on the type of ICMP you have Suricata tracks it as a flow (e.g. echo request/reply). Adding the `flow:to_server` condition probably takes it out of the “IP-only” category.

---

<div class="post-metadata">

### Author: ![Adrian\_Portas](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/adrian_portas/32/517_2.png) [@Adrian\_Portas](https://forum.suricata.io/u/Adrian_Portas)
#### Post date: [December 15, 2020, 12:49pm UTC](https://forum.suricata.io/t/i-can-only-see-the-first-alert-of-a-rule/901/3 "2020-12-15T12:49:08Z")

</div>

Hi Victor,

I didnt knew the “IP-only” behaviour. Thanks for the response!

Regards, Adrian.
