How to add multiple events at the same time to a case without using the aggregate number from Hunt? #12688
-
Version2.4.40 Installation MethodSecurity Onion ISO image Descriptionother (please provide detail below) Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU32 RAM132GB Storage for /500GB Storage for /nsm30TB Network Traffic Collectionother (please provide detail below) Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailIs there a document that you could point me towards that can show me how to send multiple events to a case at the same time or do I have to click on them one-by-one, or use the aggregate number and click on the aggregate number in the case when escalating? Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
There's no multiple select - you have to click on them one by one. If you use the aggregate number, it won't escalate the event data, just the summary of it you see in the aggregate view. |
Beta Was this translation helpful? Give feedback.
There's no multiple select - you have to click on them one by one. If you use the aggregate number, it won't escalate the event data, just the summary of it you see in the aggregate view.