Skip to main content
Solved

How the grouping of alerts happening if am using arcsight SIEM ?

  • April 27, 2021
  • 3 replies
  • 6 views

Forum|alt.badge.img+1

I know the grouping based on the entities and the time frame. to be more precise which time will it consider for the grouping? Is the base event (start time/ end time) or the alert ingestion time into Siemplify like (Triage time) . Kindly confirm?

Best answer by shakedtal

Hi @sankarakumar_R, the grouping of alerts takes the time the alert was ingested into Siemplify platform. Please let me know if you have any additional questions.

3 replies

Forum|alt.badge.img+12
  • Staff
  • Answer
  • May 3, 2021

Hi @sankarakumar_R, the grouping of alerts takes the time the alert was ingested into Siemplify platform. Please let me know if you have any additional questions.


Forum|alt.badge.img+1

Hi Shaked,

Thanks for the answer!



Forum|alt.badge.img+12
  • Staff
  • May 6, 2021

You're welcome @sankarakumar_R !