So I have a question regarding the built in aggregation option of the ESM.
Lets say I have twenty events of the same kind which have been aggregated together.
What are the perimeters of which the siem groups them together besides the "first time" field?
I worry that I am clumping together events which have different source IPs or different source users.
Solved! Go to Solution.
The default grouping is by Source IP, and Destination IP. This is customizable for each event type in the policy editor.
The default grouping is by Source IP, and Destination IP. This is customizable for each event type in the policy editor.
@r_gine If you want to aggregate on more levels, this is technically achievable by making you parser create more signature IDs. Since technically all aggregation starts with sigID then the 2 user defined properties. You do lose the control over how sensitive the aggregation is (in the receiver properties window) but often if you are needing more aggregation levels, that is unlikely to be a concern.
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA