Define when events trigger a rule on the Aggregation page of the Response Builder.
For details about product features, usage, and best practices, click ? or Help.
Next to Aggregation, select an aggregation level.
Note
Trellix recommends configuring responses for multiple events within a specific time frame rather than for every event. Otherwise, you might receive too many unwanted event notifications.
To trigger the response for every event, select Trigger this response for every event.
To trigger the event after multiple events occur, perform these steps.
Select the aggregations conditions.
— This condition is used when a distinct value of occurrence of event property is selected.
— Type the minimum defined number of events.
Next to Grouping, select whether to group the aggregated events. If you do, specify the property of the event on which they are grouped.
Click Next.