# How to combine alerts in one?

**URL:** <https://discuss.elastic.co/t/how-to-combine-alerts-in-one/266046>\
**Category:** Elastic Security\
**Created:** [March 3, 2021, 4:58am UTC](https://discuss.elastic.co/t/how-to-combine-alerts-in-one/266046 "2021-03-03T04:58:26Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![VellayLoket](https://avatars.discourse-cdn.com/v4/letter/v/13edae/32.png) [@VellayLoket](https://discuss.elastic.co/u/VellayLoket)\
**Post date:** [March 3, 2021, 4:58am UTC](https://discuss.elastic.co/t/how-to-combine-alerts-in-one/266046/1 "2021-03-03T04:58:26Z")

</div>

For example, i have infected PC in my network, and it sends many requests to C2 malware domain. So, i setup detection rule for this C2C domain and now i have got 100500 alerts from only 1 IP of infected PC. How to combine all this alerts to one (by client IP address)?

---

<div class="post-metadata">

**Author:** ![peter\_luo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/peter_luo/32/84516_2.png) [@peter\_luo](https://discuss.elastic.co/u/peter_luo)\
**Post date:** [March 3, 2021, 7:33pm UTC](https://discuss.elastic.co/t/how-to-combine-alerts-in-one/266046/2 "2021-03-03T19:33:31Z")

</div>

Is this something addressing your questions shorturl.at/tySTZ  
Not an out of box solution though.  
It is consolidating alerts, discovering patterns and grouping related alerts to cases.  
For your question: it extracts ip and groups 100500 alerts to one case and write to ELK case page.

---

<div class="post-metadata">

**Author:** ![VellayLoket](https://avatars.discourse-cdn.com/v4/letter/v/13edae/32.png) [@VellayLoket](https://discuss.elastic.co/u/VellayLoket)\
**Post date:** [March 3, 2021, 10:59pm UTC](https://discuss.elastic.co/t/how-to-combine-alerts-in-one/266046/3 "2021-03-03T22:59:57Z")

</div>

Check your link, its broken.

---

<div class="post-metadata">

**Author:** ![peter\_luo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/peter_luo/32/84516_2.png) [@peter\_luo](https://discuss.elastic.co/u/peter_luo)\
**Post date:** [March 4, 2021, 12:30am UTC](https://discuss.elastic.co/t/how-to-combine-alerts-in-one/266046/4 "2021-03-04T00:30:46Z")

</div>

here it is [Demo Video - AI-Based Analysis and Response](https://www.dtonomy.com/demo-video)

---

<div class="post-metadata">

**Author:** ![VellayLoket](https://avatars.discourse-cdn.com/v4/letter/v/13edae/32.png) [@VellayLoket](https://discuss.elastic.co/u/VellayLoket)\
**Post date:** [March 4, 2021, 12:49am UTC](https://discuss.elastic.co/t/how-to-combine-alerts-in-one/266046/5 "2021-03-04T00:49:27Z")

</div>

I'm looking for built-in functionality of ELK Stack.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 4, 2021, 3:54am UTC](https://discuss.elastic.co/t/how-to-combine-alerts-in-one/266046/6 "2021-03-04T03:54:10Z")

</div>

What version are you on?

---

<div class="post-metadata">

**Author:** ![VellayLoket](https://avatars.discourse-cdn.com/v4/letter/v/13edae/32.png) [@VellayLoket](https://discuss.elastic.co/u/VellayLoket)\
**Post date:** [March 4, 2021, 6:15am UTC](https://discuss.elastic.co/t/how-to-combine-alerts-in-one/266046/7 "2021-03-04T06:15:53Z")

</div>

7.11.0

---

<div class="post-metadata">

**Author:** ![jamesspi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamesspi/32/24479_2.png) [@jamesspi](https://discuss.elastic.co/u/jamesspi)\
**Post date:** [March 4, 2021, 7:24am UTC](https://discuss.elastic.co/t/how-to-combine-alerts-in-one/266046/8 "2021-03-04T07:24:42Z")

</div>

Hey @VellayLoket ,

Unfortunately we don't support grouping at the moment within the detections table.

Are you able to share your detection rule? We might be able to help streamline it, or perhaps provide a better strategy based on functionality that exists today.

---

<div class="post-metadata">

**Author:** ![VellayLoket](https://avatars.discourse-cdn.com/v4/letter/v/13edae/32.png) [@VellayLoket](https://discuss.elastic.co/u/VellayLoket)\
**Post date:** [March 4, 2021, 7:35am UTC](https://discuss.elastic.co/t/how-to-combine-alerts-in-one/266046/9 "2021-03-04T07:35:04Z")

</div>

The detection rule is simple:  
eventlog.category.keyword : "AM TROJAN Trojan.Johnnie.D17E73 login attempt via json-file"  
Rule type - Custom query.

---

<div class="post-metadata">

**Author:** ![jamesspi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamesspi/32/24479_2.png) [@jamesspi](https://discuss.elastic.co/u/jamesspi)\
**Post date:** [March 4, 2021, 7:57am UTC](https://discuss.elastic.co/t/how-to-combine-alerts-in-one/266046/10 "2021-03-04T07:57:15Z")

</div>

Thanks - would detecting when a threshold (say, more than 10 times) is met for this be a better/cleaner way then for every single instance? Would it serve your use case?

---

<div class="post-metadata">

**Author:** ![VellayLoket](https://avatars.discourse-cdn.com/v4/letter/v/13edae/32.png) [@VellayLoket](https://discuss.elastic.co/u/VellayLoket)\
**Post date:** [March 4, 2021, 8:00am UTC](https://discuss.elastic.co/t/how-to-combine-alerts-in-one/266046/11 "2021-03-04T08:00:07Z")

</div>

It depends on walware type.  
If malware ask his C2 one time a day - it would be better to use Custom Query to alert every queries.  
If malware ask his C2 every 5 times - it would be beter to use your variant (more than 10 times), but anyway we gonna get many alerts even if we gonna use threshold variant (nto 100500 alert but 500 alerts with the same IP address)

---

<div class="post-metadata">

**Author:** ![jamesspi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamesspi/32/24479_2.png) [@jamesspi](https://discuss.elastic.co/u/jamesspi)\
**Post date:** [March 4, 2021, 8:06am UTC](https://discuss.elastic.co/t/how-to-combine-alerts-in-one/266046/12 "2021-03-04T08:06:45Z")

</div>

Yeah, I agree.

What frequency does the rule run at? How long did it take to get to 100500 alerts?

---

<div class="post-metadata">

**Author:** ![peter\_luo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/peter_luo/32/84516_2.png) [@peter\_luo](https://discuss.elastic.co/u/peter_luo)\
**Post date:** [March 4, 2021, 6:08pm UTC](https://discuss.elastic.co/t/how-to-combine-alerts-in-one/266046/13 "2021-03-04T18:08:10Z")

</div>

It makes sense to me that you'd want to reduce the number of alerts, but thresholding is often either too quiet or too noisy. I think the only way to solve this is with another layer of logic. What I've found, working at Microsoft SOC and with a number of others, is that we can lookback to reduce/group alerts and also correlate them to other events that indicate other activities that provide more context to the C2. For instance, we've been able to correlate C2 events to malware detection events (and sometimes even abnormal login events before those). We've also seen these events correlate to other beaconing events and data exfiltration. Based on this, we've been able to mitigate earlier in the attack chain.

---

<div class="post-metadata">

**Author:** ![VellayLoket](https://avatars.discourse-cdn.com/v4/letter/v/13edae/32.png) [@VellayLoket](https://discuss.elastic.co/u/VellayLoket)\
**Post date:** [March 4, 2021, 11:09pm UTC](https://discuss.elastic.co/t/how-to-combine-alerts-in-one/266046/14 "2021-03-04T23:09:57Z")

</div>

Right now the rule create alert on every malware request, we have several PCs with this indicator so we got 2-3 alerts every minute. But, as i said before if we use correlation with threshold ( \>100 event or \> 1000) than we gonna be blind to malware wich send requests 1 a day. It will be very usefull if ELK can combine event with client.ip address and with the same event categories.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 1, 2021, 11:10pm UTC](https://discuss.elastic.co/t/how-to-combine-alerts-in-one/266046/15 "2021-04-01T23:10:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
