How often do baseline event connectors retrieve events?
Which attribute correlates multiple events to one alert?
What attribute is used to consolidate events into a single alert?
Which attribute within an event needs to be exactly the same to allow for deduplication?
In default configuration using baseline connectors, how often is event data collected from event sources?
When creating an alert management rule, where would you specify a workflow to resolve a given condition?