Define your own custom similarity strategy
From an alert you can access (if applicable) a list of "similar alerts" that we automatically group together for you to facilitate your investigation.
These "similar alerts" are based on identical fields in the events.
Until now these strategies were not accessible or editable.
You can now see, create or update this similarities strategies at the rule level.