Aggregation Rule

It doesn't have the [aggregated_count] field originally; the example of the event you can see just in the beginning of my post.

I don't really know how to see the aggregate (filtered) events; i tried using tcpdump, but the events are just the same. The thing is, i send these events to SIEM, and it comes to SIEM just the same. So i think the rule doesn't work.