Scheduled Maintenance for the Case Portal during May 27-29
Alerts are not grouping into a Single Incident, In Incident Rule we are grouping Alerts based on the Source IP within in one hour.
In that case of 1 hours , all the alerts relates to the source IP should be grouped under one Incident but it is not happening.
PFA of Incident Screenshot & Incident Rule Screenshot,
please help us on this issue.
Hi @socuser ,
This grouping works as expected as each incident has 1000 alerts.
rsa.respond.alertrule.batch-size=1000 value decides how many alerts are part of each incident.