I need a solution
Hi all
Challenge is to detect mass mailings on endpoints to externel recipients and popup a warning in case a definable number (X) of externe recipients is exceeded.
Here is what I tried (unsuccessfully until now):
- Groups Rules: Detect all recipients with *@* (actually catches all recipients) added a counter to X=20 to ensure that no incident is created with less
- Groups Exception: Ignore Recipients matching "internal.com"
Behaviour: Works nice in all test cases. Testcase where external and internal in total exceeds X=20 also matches even if the externals are less than X=20.
So I need a way, where the exceptions (internals) are properly deducted from the total of recipients or the internal are not matched at all (best case)
appreciate any ideas or solutions.
Rgds
Thomas
0