Which of the following represents the correct relation of alerts to incidents?
Select an option, then click Submit answer.
-
○
Only alerts with the same host are grouped together into one Incident in a given time frame.
-
○
Alerts that occur within a three hour time frame are grouped together into one Incident.
-
○
Alerts with same causality chains that occur within a given time frame are grouped together into an Incident.
-
○
Every alert creates a new Incident.