---
title: "Using the Events Per Second Rule Setting"
canonical: "https://docs.infoblox.com/space/nios85/35753395/Using%20the%20Events%20Per%20Second%20Rule%20Setting"
format: markdown
---
The **Events** **per** **second** setting allows for disabling or throttling of event logs for specific threat protection rules. The default value is one and the maximum value is 700. NIOS displays an error message when you enter a value greater than the maximum value. You can override this event filter at the member level. 

Setting the **Events** **per** **second** parameter to zero disables logging for that rule. Setting the parameter to any other number enables threat protection logging for that specific rule. For information about how to configure this, see *<span style="color: #0000ff">[Configuring](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35946661)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35946661)*<span style="color: #0000ff">[Grid](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35946661)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35946661)*<span style="color: #0000ff">[Security](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35946661)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35946661)*<span style="color: #0000ff">[Properties](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35946661)</span>*.

Make note of the following guidelines when you enter a value in the **Events** **per** **Second** **per** **Rule** field:

- The value of this field is applicable only for rules that do not have `event-filter` as part of their format. The following is an example of a rule that has `event-filter` in its format:  
`drop udp any any -> any 53 (msg:"EARLY DROP UDP DNS named author attempts"; content:"|07|authors|04|bind|00|"; offset:12; sid:110100100; rev:1;) event_filter gen_id 1, sig_id 110100100, type limit, track by_src, count 1, seconds 1`
- For rules that have `event-filter` as part of their format, the event-filter precedes the value in the **Events**<span style="color: #172b4d"> </span>**per**<span style="color: #172b4d"> </span>**Second**<span style="color: #172b4d"> </span>**per**<span style="color: #172b4d"> </span>**Rule**<span style="color: #172b4d"> field.</span>
- Therefore, for rules that have `event-filter` as part of their format, to disable event logging for Threat  Protection, you must disable it at the rule-level by modifying the syslog file. For rules that do not have `event-filter` as part of their format, to disable event logging for Threat Protection, set 0 in the **Events per Second per Rule** field.