cancel
Showing results for 
Search instead for 
Did you mean: 

Question regarding aggregation

Jump to solution

So I have a question regarding the built in aggregation option of the ESM.
Lets say I have twenty events of the same kind which have been aggregated together.
What are the perimeters of which the siem groups them together besides the "first time" field?
I worry that I am clumping together events which have different source IPs or different source users.

1 Solution

Accepted Solutions
Highlighted
Reliable Contributor brenta
Reliable Contributor
Report Inappropriate Content
Message 2 of 4

Re: Question regarding aggregation

Jump to solution

The default grouping is by Source IP, and Destination IP. This is customizable for each event type in the policy editor.

Brent
3 Replies
Highlighted
Reliable Contributor brenta
Reliable Contributor
Report Inappropriate Content
Message 2 of 4

Re: Question regarding aggregation

Jump to solution

The default grouping is by Source IP, and Destination IP. This is customizable for each event type in the policy editor.

Brent
r_gine
Level 9
Report Inappropriate Content
Message 3 of 4

Re: Question regarding aggregation

Jump to solution
Lets hope you don't need to either aggregate more than two fields or aggregate of fields that McAfee has placed restrictions on... I imagine you'll eventually need/want to aggregate on a really important field that is not available for aggregation.
Reliable Contributor brenta
Reliable Contributor
Report Inappropriate Content
Message 4 of 4

Re: Question regarding aggregation

Jump to solution

@r_gine If you want to aggregate on more levels, this is technically achievable by making you parser create more signature IDs. Since technically all aggregation starts with sigID then the 2 user defined properties. You do lose the control over how sensitive the aggregation is (in the receiver properties window) but often if you are needing more aggregation levels, that is unlikely to be a concern.

Brent
More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator
  • Community Help Hub

      New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

    • Find Forum FAQs
    • Learn How to Earn Badges
    • Ask for Help
    Go to Community Help

    Join the Community

      Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

    • Get helpful solutions from McAfee experts.
    • Stay connected to product conversations that matter to you.
    • Participate in product groups led by McAfee employees.
    Join the Community
    Join the Community