Good day for everyone,
I've built multiple use-cases through correlation search.
The concern here , I am getting multiple alerts for same case.
how can I set it to give only one alert contain all data.
screenshot can explain more:
Hi @Sultan77 ,
this means that many Correlation Searches (or Detections from 8.X) triggered events.
It isn't a good idea grouping different Detections in one alert.
Anyway, the only solution is disable Notable (or Finding) creation and use only Risk Score, then use a Finding Based Detection to have only one Finding containing all the others.
In addition, you can group more Findings in one Investigation.
Ciao.
Giuseppe
Dear @gcusello
Can you explain how to group more than one finding in one investigation?
Hi @Sultan77 ,
if you have ES 7.x, you have to flag all the events and add to the same investigation.
I haven't an ES 8.x to guide you in this case.
Ciao.
Giuseppe