I want to set up a custom alert for 3 events, is that possible with the advanced correlation feature?
For example I currently have email alerts for:
- User account created
- User account modified
- User account enabled
When I create a new account, I get all three alerts. However, I only want to get one alert.
So I created an advanced configuration that has all three event IDs for the previously mentioned alerts. Then under advanced correlations, I set to 10 seconds and matching the same domain. I created a new alert using the custom rule.
Now I still get the 3 events within 10 seconds, but nothing shows up when I look at the custom report. What could I be missing here?
Thanks