Disable network traffic-based alert grouping
Disable network traffic-based alert grouping to prevent alerts from being grouped solely by network activity, reducing noise during traffic spikes and ensuring critical issues stand out for quicker resolution.
Vorbereitungen
Role required: evt_mgmt_admin
Warum und wann dieser Vorgang ausgeführt wird
Prozedur
- Navigate to .
- Clear that check box for the property Enable Network Traffic correlation (sa_analytics.agg.query_network_traffic_correlation_enabled).
- Set the property sa_analytics.enable_process_mapping_calculation to false.