Found the answer in one of the built-in rules:
Apply Device Stopped Sending Events (Firewall, IPS, VPN or Switch) on events which are detected by the Local system
and when none of BB:DeviceDefinition: FW / Router / Switch, BB:DeviceDefinition: IDS / IPS, BB:DeviceDefinition: VPN match in 30 minutes after BB:DeviceDefinition: FW / Router / Switch, BB:DeviceDefinition: IDS / IPS, BB:DeviceDefinition: VPN match with the same Log Source
------------------------------
Simon S.
------------------------------