Attached is a spread sheet of events that all have triggered the same excessive login rule. We are not sure why some of these events have "Agent Aggregate Event" as the name and other have a real name with more meaning. I can't seem to find any differences in the events as to why some are parsed out differently so I'm not sure where to start looking for the problem. We would like the name field to not have "Agent Aggregate Event" and keep the true name. Device Custom String3 is the only difference I see in any of these events but I don't see what that has to do with the name of the event. Any help would be great. I excluded real IP's and User Names for obvious reasons.