Rule Aggregation Doesn't work
I have created a standard rule to identify windows failed logon events. I want to set a counter to fire a rule when 5 such events are generated within 2 mins then fire the rule. I set the aggregation to '# Of matches = 5" and "Time frame = 2 Minutes". but It seems not working properly. each time an event comes to the ESM , the rule will be fired.
Any one met this before? any solutions?
Re: Rule Aggregation Doesn't work
please open the "Actions" tab on that rule and check the type of action enabled. Probably you have the option "On Every Event" enabled, while you should check "On Every Threshold".