So Threat Prevention suppresses logs of substantially similar attacks that are run over and over to avoid overwhelming the logs. For the IPS blade logs the suppression interval is 2 minutes as specified here:
sk108423: IPS generates Alerts instead of Logs
However the SK below states that the suppression interval for all Threat Prevention logs (which I'm assuming is including IPS) is 600 minutes (10 hours):
sk115876: Some fields are missing from IPS or Threat Prevention logs
So which is it? My guess is that the 2 minute suppression period for IPS was true for R77.30 and earlier, but when IPS was rolled up into the rest of Threat Prevention in R80.10 it inherited the 10 hour suppression period? I suppose I could set this up in my lab and try it but I thought it would be faster just to ask.
Because this will probably have be answered by R&D paging @PhoneBoy
Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com