The Alerts table displays one row for each alert or alert group. When multiple alerts occur on the same host for the same indicator of compromise (IOC), for example, over a period of time, those alerts appear as one row in the alerts table.
Alerts include Agent ID, which affects how alerts are grouped. Two alerts from different agents are never included in the same group.
The following sections describe alert groups for malware, IOC, exploit detection, and generic alerts.
Malware alert grouping
Malware alerts are grouped if they have the same MD5 hash, file path, malware name, scan type, and signature information. When grouped, they are shown as one alert with multiple instances.
Note
Alerts generated from a malware boot scan are grouped by infection name only.
IOC alert grouping
IOC alerts are grouped by condition identifier.
Exploit alert grouping
Alerts based on exploit detection are grouped by timestamp, file path, and MD5 hash.
Process Tracker alert grouping
Alerts grouped by new process events tracked by the Process Tracker Module.
Generic (General) alert grouping
Generic alerts are dynamically grouped by parameter attributes defined in the alert data.