Kaspersky Unified Monitoring and Analysis Platform

Aggregation rules

Aggregation rule resources are used to group repeated events into aggregation events.

Available settings:

  • Name (required)—a unique name for this type of resource. Must contain from 1 to 128 Unicode characters.
  • Tenant (required)—name of the tenant that owns the resource.
  • Threshold—the number of events that should be received before the aggregation rule is triggered and the events are aggregated. The default value is 100.
  • Lifetime (required)—time period (in seconds) during which events are received for aggregation. On the timeout, the aggregation rule is triggered and a new event is created. The default value is 60.
  • Description—up to 256 Unicode characters describing the resource.
  • Identical fields (required)—in this drop-down list you can select fields that should be used to group events for aggregation.
  • Unique fields—in this drop-down list you can select the fields that will disqualify events from aggregation even if their Identical fields parameter match the aggregation rule condition.
  • Sum fields—in this drop-down list, you can select the fields whose values should be summed during aggregation.
  • Filter—settings block in which you can specify the conditions for identifying events that will be processed by the aggregation rule resource. You can select an existing filter resource from the drop-down list, or select Create new to create a new filter.

    In aggregation rule resources, do not use filters with the TI operand or the TIDetect and inActiveDirectoyGroup operators. The Active Directory fields for which you can use the inActiveDirectoyGroup operator will appear during the enrichment stage (after aggregation rules are executed).

    Creating a filter in resources