Hi,
I want to create a Correlation alert that will trigger and collect all the events from the same IP within a certain time. I try to "group by", but, not work
THX
@LIP
can you share sample events and the search you're trying to run ?