Skip to main content

Q 1:  limitations around the alerts ingested into SecOps

Q 2: Different options to perform grouping by different conditions

A1: Platform limits around ingest are documented here: https://cloud.google.com/chronicle/docs/soar/admin-tasks/advanced/service-limits#ingestion-limits

A2: Docs on grouping options are here: https://cloud.google.com/chronicle/docs/soar/investigate/working-with-alerts/alert-grouping-mechanism-admin but pay particular attention to the use cases, they do a pretty good job of outlining what might lead you to choose the different options.


 


As @JeremyLand mentioned these are possible ways to understand and control alerts grouping. 

You might also want to understand how Alert overflow is handled, you will find those settings on the alert grouping configuration page.

However, it would great to have a feature while allows alert throttling basis of common entities or other UDN fields. This I believe is not yet available in Rules as of now. 


Reply