So I have a question regarding the built in aggregation option of the ESM.
Lets say I have twenty events of the same kind which have been aggregated together.
What are the perimeters of which the siem groups them together besides the "first time" field?
I worry that I am clumping together events which have different source IPs or different source users.
Solved! Go to Solution.
@r_gine If you want to aggregate on more levels, this is technically achievable by making you parser create more signature IDs. Since technically all aggregation starts with sigID then the 2 user defined properties. You do lose the control over how sensitive the aggregation is (in the receiver properties window) but often if you are needing more aggregation levels, that is unlikely to be a concern.