when i create a rule the dedup key in conditions should be. (.*). so any incident with the same dedup key will be suppressed ?
If an alert is suppressed, subsequent alerts with the same deduplication key will still trigger a new incident, unless those events are also suppressed. This is because deduplication only merges alerts when there is an existing open incident. Since suppressed alerts do not create an incident, subsequent alerts with the same dedup key can potentially trigger a new incident unless they are also suppressed by a rule.
If you have any further questions, please don’t hesitate to reach out.