cancel
Showing results for 
Search instead for 
Did you mean: 
Highlighted

Question regarding aggregation

Jump to solution

So I have a question regarding the built in aggregation option of the ESM.
Lets say I have twenty events of the same kind which have been aggregated together.
What are the perimeters of which the siem groups them together besides the "first time" field?
I worry that I am clumping together events which have different source IPs or different source users.

1 Solution

Accepted Solutions
Reliable Contributor brenta
Reliable Contributor
Report Inappropriate Content
Message 2 of 4

Re: Question regarding aggregation

Jump to solution

The default grouping is by Source IP, and Destination IP. This is customizable for each event type in the policy editor.

Brent
3 Replies
Reliable Contributor brenta
Reliable Contributor
Report Inappropriate Content
Message 2 of 4

Re: Question regarding aggregation

Jump to solution

The default grouping is by Source IP, and Destination IP. This is customizable for each event type in the policy editor.

Brent
r_gine
Level 9
Report Inappropriate Content
Message 3 of 4

Re: Question regarding aggregation

Jump to solution
Lets hope you don't need to either aggregate more than two fields or aggregate of fields that McAfee has placed restrictions on... I imagine you'll eventually need/want to aggregate on a really important field that is not available for aggregation.
Reliable Contributor brenta
Reliable Contributor
Report Inappropriate Content
Message 4 of 4

Re: Question regarding aggregation

Jump to solution

@r_gine If you want to aggregate on more levels, this is technically achievable by making you parser create more signature IDs. Since technically all aggregation starts with sigID then the 2 user defined properties. You do lose the control over how sensitive the aggregation is (in the receiver properties window) but often if you are needing more aggregation levels, that is unlikely to be a concern.

Brent
More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator