2015-12-09 10:57 AM
We are using RSA SA 10.4 AIO without ESA.
How can I configure alerts such that when X amount of alerts come in of the same event, only one alert gets sent to the recipients displaying the times the event occurred.
Use Case:
A group got added to the local administrators group on multiple systems within 5 minutes of each other. Currently, we will get 10 email alerts in a row. We would like one email alert showing all 10 events when it occurs within specified time frame. Eg. Within 5 minutes
2015-12-10 11:43 AM
Hello
I dont think this is possible with just he reporting engine and no ESA. It is not possible to combine alerts into one email. This is a use case for an ESA I'm afraid. With the reporting engine, you can either have the alerts sent or not.
2015-12-10 11:43 AM
Hello
I dont think this is possible with just he reporting engine and no ESA. It is not possible to combine alerts into one email. This is a use case for an ESA I'm afraid. With the reporting engine, you can either have the alerts sent or not.