Q 1: limitations around the alerts ingested into SecOps
Q 2: Different options to perform grouping by different conditions
Q 1: limitations around the alerts ingested into SecOps
Q 2: Different options to perform grouping by different conditions
A1: Platform limits around ingest are documented here: https://cloud.google.com/chronicle/docs/soar/admin-tasks/advanced/service-limits#ingestion-limits
A2: Docs on grouping options are here: https://cloud.google.com/chronicle/docs/soar/investigate/working-with-alerts/alert-grouping-mechanism-admin but pay particular attention to the use cases, they do a pretty good job of outlining what might lead you to choose the different options.
As @JeremyLand mentioned these are possible ways to understand and control alerts grouping.
You might also want to understand how Alert overflow is handled, you will find those settings on the alert grouping configuration page.
However, it would great to have a feature while allows alert throttling basis of common entities or other UDN fields. This I believe is not yet available in Rules as of now.
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.