Refer to the exhibit.

An analyst is troubleshooting the rule shown in the exhibit. It is not generating any incidents, but the filter parameters are generating events on the Analytics tab.
What is wrong with the rule conditions?
The Group By attributes - Destination IP and User - cause the aggregation (COUNT(Source IP) >= 2) to apply within each unique combination of those groupings. This restricts the count calculation and can prevent the rule from triggering incidents, even if matching events exist in the Analytics tab.
Portia
2 months agoRosenda
2 months agoKristian
2 months agoJackie
3 months agoAracelis
3 months agoLeah
3 months agoNoel
3 months agoMarylin
4 months agoSilvana
4 months agoAnglea
4 months agoAlonzo
4 months agoMargurite
4 months agoRodolfo
4 months agoEladia
5 months ago