Plugins

Query: List alerts by aggregate_id

Description

Group related alerts together using the aggregate_id, which represents the Agent ID & Process Tree ID, similar to the legacy detection_id.

Query

Tables used in this query:

SQL