Understanding alert groups

Prev Next

The Alerts table displays one row for each alert or alert group. When multiple alerts occur on the same host for the same indicator of compromise (IOC), for example, over a period of time, those alerts appear as one row in the alerts table.

Alerts include Agent ID, which affects how alerts are grouped. Two alerts from different agents are never included in the same group.

The following sections describe alert groups for malware, IOC, exploit detection, and generic alerts.

Malware alert grouping

Malware alerts are grouped if they have the same MD5 hash, file path, malware name, scan type, and signature information. When grouped, they are shown as one alert with multiple instances.

Note

Alerts generated from a malware boot scan are grouped by infection name only.

IOC alert grouping

IOC alerts are grouped by condition identifier.

Exploit alert grouping

Alerts based on exploit detection are grouped by timestamp, file path, and MD5 hash.

Process Tracker alert grouping

Alerts grouped by new process events tracked by the Process Tracker Module.

Generic (General) alert grouping

Generic alerts are dynamically grouped by parameter attributes defined in the alert data.