I had two internal users have a teams meeting that kicked off "alert.signature: ET INFO Session Traversal Utilities for NAT (STUN Binding Response)" which then blocked all the Microsoft Teams Servers.
I went into the rule and set a threshold on the first of many ip addresses that were blocked as the teams call moved around the MS estate as each one got blocked.
Then I realised that maybe that wasnt the best way and I was going to set a threshold on all of the MS Teams range BUT I cant work out how to remove a set threshold,
I can add them but how do I remove them from the rule?
Tim