KBI 310428 Combining Events for Alerts In Argent for Compliance
Version
Argent AT 3.1A-1301-E or above
Date
28 Apr 2013
Summary
Argent for Compliance allows one alert for one event occurrence, as well as one combined alert for multiple occurrences of the same event.
Technical Background
By default, Argent for Compliance fires one alert for each matching event for Windows Event Logs, which is different from Argent XT when multiple occurrences of the same event are listed in the same alert.
Argent for Compliance can be configured to behave the same as Argent XT.
This done by setting the registry ‘COMBINE_ALERTS_ON_LOG_EVENT’ to 1. A sample event looks like following:
Resolution
N/A