Define filter and aggregation criteria
Define and set filter conditions to specify which incoming CrowdStrike Next-Gen SIEM detections should create security incidents. You can also define additional detection field criteria that allows an incoming detection to be appended to an open security incident instead of creating an incident.
Set filtering conditions
Set the filtering conditions so that security incidents are created only when the filtering conditions match.
Before you begin
Role required: sn_si.ingestion_profile_admin
About this task
This type of filtering helps you to isolate security incidents and limits the number of security incidents that you create. If you set additional filtering criteria, only the required detections are ingested without having to change the query or the triggered detection configuration.
Procedure
Define aggregation conditions
Define additional incident aggregation criteria that aggregates an incoming detection to an existing SIR security incident instead of creating similar, potentially duplicate detections. When you use field matching value criteria for each profile, this additional aggregation can reduce the number of active, overlapping security incidents by placing all related detections data on a single security incident.
Before you begin
Role required: sn_si.ingestion_profile_admin
About this task
All the aggregated incidents on a security incident are displayed on the CrowdStrike Next-Gen SIEM Aggregated Incidents related list. This list details the associated timestamps and aggregated field values. This information helps you understand why incidents are added to the existing security incidents.
Procedure
What to do next
Set a schedule to retrieve the incident data and ingested incidents that match the criteria in the profile.