Aggregation settings apply to all events generated by a device. You can create exceptions for individual rules if the general settings don't apply to the events generated by that rule.
On the views pane, select an event generated by the rule you want to add an exception for.
Click the Menu icon
, then select Modify Aggregation Settings.Select the field types you want to aggregate from the Field 2 and Field 3 drop-down lists.
Important
The fields you select in Field 2 and Field 3 must be different types or an error results. When you select these field types, the description for each aggregation level changes to reflect the selections you made. The time limits for each level depend on the event aggregation setting you defined for the device.
Click OK to save your settings, then click Yes to continue.
Deselect devices if you do not want to roll out the changes to them.
Click OK to roll out the changes to the devices that are selected.
The Status column shows the status of the update as the changes are rolled out.