Kaspersky Next XDR Expert

Managing aggregation rules

This section contains general information about aggregation rules and gives instructions on how to create, edit, duplicate, copy to another tenant, and delete aggregation rules.

Kaspersky Next XDR Expert allows you to create aggregation rules to combine repetitive events of other Kaspersky solutions into Open Single Management Platform alerts. You can create and manage aggregation rules in the Aggregation rules section of tenant properties.

Also, the Aggregation rules section contains the predefined aggregation rule created by Kaspersky experts. This rule combines the events for which the same correlation rule was triggered during the default aggregation interval (30 seconds).

You cannot delete the predefined aggregation rule, but you can edit it. By default, the rule is enabled and always displayed in the list of aggregation rules with the Kaspersky Lab value in the Created by column.

To manage aggregation rules, you must have one of the following XDR roles: Main administrator, Tenant administrator, SOC administrator.

The aggregation rules are triggered according to the specified priority. The higher the rule is in the list of aggregation rules, the higher its priority. If you want to change the aggregation rule priority, you have to drag and drop the rule by clicking its name.