2022-01-06 03:57 AM
Hi Team,
Alerts are not grouping into a Single Incident, In Incident Rule we are grouping Alerts based on the Source IP within in one hour.
In that case of 1 hours , all the alerts relates to the source IP should be grouped under one Incident but it is not happening.
PFA of Incident Screenshot & Incident Rule Screenshot,
please help us on this issue.
Regards,
SOC TEAM
2022-03-06 04:36 AM
Hi @socuser ,
This grouping works as expected as each incident has 1000 alerts.
rsa.respond.alertrule.batch-size=1000 value decides how many alerts are part of each incident.
2022-06-23 01:14 AM
Hi @socuser
I'm facing the same issue. Did you find any solution?
2022-07-05 12:52 AM
Not yet