How the grouping of alerts happening if am using arcsight SIEM ?

I know the grouping based on the entities and the time frame. to be more precise which time will it consider for the grouping? Is the base event (start time/ end time) or the alert ingestion time into Siemplify like (Triage time) . Kindly confirm?

Solved Solved
0 3 278
1 ACCEPTED SOLUTION

Hi @sankarakumar_R, the grouping of alerts takes the time the alert was ingested into Siemplify platform. Please let me know if you have any additional questions.

View solution in original post

3 REPLIES 3

Hi @sankarakumar_R, the grouping of alerts takes the time the alert was ingested into Siemplify platform. Please let me know if you have any additional questions.

Hi Shaked,

Thanks for the answer!


You're welcome @sankarakumar_R !