How the grouping of alerts happening if am using arcsight SIEM ?

I know the grouping based on the entities and the time frame. to be more precise which time will it consider for the grouping? Is the base event (start time/ end time) or the alert ingestion time into Siemplify like (Triage time) . Kindly confirm?

Solved Solved
0 3 282
1 ACCEPTED SOLUTION

Hi @sankarakumar_R, the grouping of alerts takes the time the alert was ingested into Siemplify platform. Please let me know if you have any additional questions.

View solution in original post

3 REPLIES 3