2016-10-20 10:43 AM
Is there anyone tried to create aggregation rules in ESA?..I want to group by any Meta Key but not limiting with counts since I don't want to miss single event.
The issue is sometime I'm getting flooded by email notifications for the particular alert, I knew about email suppression, if I enable it then there is a possibility to miss the notification for new alert. Thanks!!
2016-10-20 10:51 AM
Lee's answer to https://community.rsa.com/thread/189008 may help you.
2016-10-20 11:27 AM
I saw that one, tried only with GROUP BY & OUTPUT LAST conditions but doesn't work. Looking for the more & tested queries. Thanks!!