Please look at security_content/detections/network/internal_vertical_port_scan.yml The src_port seems unnecessary and probably expensive please remove this (around line 19) values(All_Traffic.src_port) as src_port