KBI 310428 Combining Events for Alerts In Argent for Compliance

Version

Argent AT 3.1A-1301-E or above

Date

28 Apr 2013

Summary

Argent for Compliance allows one alert for one event occurrence, as well as one combined alert for multiple occurrences of the same event.

Technical Background

By default, Argent for Compliance fires one alert for each matching event for Windows Event Logs, which is different from Argent XT when multiple occurrences of the same event are listed in the same alert.

Argent for Compliance can be configured to behave the same as Argent XT.

This done by setting the registry ‘COMBINE_ALERTS_ON_LOG_EVENT’ to 1. A sample event looks like following:




Click For Full Size

Resolution

N/A