Hi,
You just need to get the correlation side of things squared away in your rule and you will be fine.
Under Correlation Time change 1 to 100 and within 30 seconds to your desired time window (e.g. 3 minutes). The response window is a bit of a mystery to me too and I have typically left this setting alone for fear of breaking the rules. If you need to get complex, you can use the advanced correlation configuration (gear icon). You will need to identify how long it takes for LEM to receive 100 simultaneous login events and ensure this also fits in with your window you want to fire a rule for this activity, else you rule may not fire, or fire false alerts.
To send SNMP traps you need to configure the SNMP active response connector and email the SMTP active response connector. Your rule will need to be relevant, but if you want it to fire on only say 10 usernames, create a user defined group and set your event correlation to contain that group.