Create incident consolidation rules
Create incident consolidation rule to consolidate multiple incidents of similar nature under one parent incident.
Before you begin
Role required:
- sn_dlir.admin - Create, edit, and delete
- sn_dlir.analyst and sn_dlir.analyst_read - View (read-only)
About this task
The DLP admin defines these incident consolidation rules to automatically consolidate the DLP incidents of same nature under one parent incident. The DLP incident consolidation rule enables you to consolidate the DLP incidents based on configuration provided for Consolidation duration and Consolidation identification.
Note:
When a consolidated incident is created, it becomes a child of the parent DLP incident. If the severity of the consolidated incident is higher than that of the parent, then the parent incident severity will be updated to match with the child incident.