Hello everyone,
Please can someone elaborate on this, differentiating between Group entities and source grouping identifiers and what happens when this is toggled on ?
Group entities and source grouping identifiers in the same case
Hi
Source grouping identifier is a way to group alerts by external identifier such as Qradar offense ID (for example, in Qradar alerts are being grouped in the product).
When the toggle is turned on - it means that it will try to group by the source grouping identifier (qradar) and if not - it will group by mutual entities
The source grouping identifier is integrated in the connector's logic (e.g. Qradar Correlation Events Connector V2)
View files in slack
Thanks for the enlightenment
Hi
Reply
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.