Hi All,
In Chronicle Soar,
3 different Alerts from falcon have been grouped into a single case
note: grouping condition defined is if all entities match then all only it should group
But what happened is that alerts are being grouped together even when not all entities meet the specified grouping conditions, which require all entities to match.
Question:
Why are these alerts being grouped into a case when not all entities are matching?


