Good afternoon all!
I was wondering if one of the Siemplify Wizards in the community could help me out with alert grouping.
We have an Exchange connector that pulls header data from attached .eml files within messages that get sent to a specific inbox. See below:
View files in slack
From there using a Visual Family configuration, we specify the headers values that should get assigned as entities:
View files in slack
Then in alert grouping we have the settings below:
View files in slack
But we are still seeing alerts that should be grouped together in separate cases. Does anyone know what I am doing wrong?
Hi
Based on the third image the rule applies only to alerts with the EXACT name in the "Value" column.
The name contains an email address that might change from alert to alert.
This might be a reasons.
What do you think?
Hey
If the Alert Type is exactly the same in all those alert - then should be good.
Just something worth checking.
Also - I would try setting the Grouping Entities to a single entity first.
I see. Can you take a look at the config below and tell me if Siemplify should now properly group the alerts in order?
View files in slack
As you can see, I've changed the configuration so that anything from the Exchange connector should group by generic entity which is specified in the Visual Family configuration.
I see. Can you take a look at the config below and tell me if Siemplify should now properly group the alerts in order?
View files in slack
Hey