> For the complete documentation index, see [llms.txt](https://docs.inopli.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.inopli.com/response/rules/rule-details.md).

# Rule Details

### **Incident Description**

**Incident Description:** a designated space to <mark style="color:green;">insert the description of the incident</mark> that will be opened by this correlation rule.

**Disable Alert Grouping:** This option, <mark style="color:green;">when activated, instructs Inopli to open an independent incident for each unique value identified in the grouping field</mark>. If this option is deactivated, Inopli will identify multiple attackers responsible for the same incident and group them together.

<figure><img src="https://2621223932-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLTQJomzpe5BTzHSLQPAt%2Fuploads%2FFZCvDpC6hz6Tw0alAYOQ%2FScreenshot%202023-12-30%20at%2014.11.42.png?alt=media&amp;token=f5b68007-6e9f-43d5-8a4c-ef6d2f8f764c" alt=""><figcaption><p>Incident Description Stage</p></figcaption></figure>

***

### **Grouping**

Extremely necessary for the activation of the rule. <mark style="color:green;">It determines which field is necessary for Inopli to use in the treatment process</mark>, usually the field identifying the origin of the attack, with the possibility of configuring one or more for each SIEM.

<figure><img src="https://2621223932-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLTQJomzpe5BTzHSLQPAt%2Fuploads%2F5GvVDjRGqqnwSotKhvLV%2FScreenshot%202023-12-30%20at%2014.12.06.png?alt=media&amp;token=600a24c2-27e5-4e84-a6a5-8504008c71dd" alt=""><figcaption><p>Grouping Stage</p></figcaption></figure>

***
