Aggregation is set as the default and aggregated events have fields that match. You can choose the type of aggregation for all events generated on a device. Then, you can change the aggregation settings for individual rules.
You must have Policy Administrator and Device Management or Policy Administrator and Custom Rules permissions to change these settings.
Note
Event aggregation and flow aggregation are enabled by default, and set on Medium High.
Event aggregation is only available for Trellix Application Data Monitor devices and Trellix Enterprise Security Manager - Event Receivers, and flow aggregation is available for Trellix Enterprise Security Manager - Event Receivers.
In the Policy Editor, select the rule for which you want to change aggregation settings
Click → .
From the Field 2 and Field 3 drop-down lists, select the field types you want to aggregate.
Note
The selected fields must differ or be an error results. Level 1, 2, and 3 aggregation descriptions change based on your selections.
Save the settings.
The Aggregation Exceptions Rollout lists the status of devices affected by your changes. Out-of-date devices are checked. Deselect the devices you do not want to apply the changes to, then click OK to roll out the changes.