KBI 310428 Combining Events for Alerts In Argent for Compliance


Argent AT 3.1A-1301-E or above


28 Apr 2013


Argent for Compliance allows one alert for one event occurrence, as well as one combined alert for multiple occurrences of the same event.

Technical Background

By default, Argent for Compliance fires one alert for each matching event for Windows Event Logs, which is different from Argent XT when multiple occurrences of the same event are listed in the same alert.

Argent for Compliance can be configured to behave the same as Argent XT.

This done by setting the registry ‘COMBINE_ALERTS_ON_LOG_EVENT’ to 1. A sample event looks like following:

