I have a couple of sendmail rules that I need to handle differently. For example, the fact that an IP was rejected by RBL isn't something I want to hear about immediately.
I DO want to hear about it if that same IP triggered that alert more than X times (frequency); then I would drop them in a firewall table. My question is how to properly tune that rule so that it doesn't report unless it gets hit at a certain frequency. _F
