> For the complete documentation index, see [llms.txt](https://docs.inopli.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.inopli.com/response/rules/rule-details.md).

# Rule Details

### **Incident Description**

**Incident Description:** a designated space to <mark style="color:green;">insert the description of the incident</mark> that will be opened by this correlation rule.

**Disable Alert Grouping:** This option, <mark style="color:green;">when activated, instructs Inopli to open an independent incident for each unique value identified in the grouping field</mark>. If this option is deactivated, Inopli will identify multiple attackers responsible for the same incident and group them together.

<figure><img src="/files/fXXGvKZezdEK0PATlFoP" alt=""><figcaption><p>Incident Description Stage</p></figcaption></figure>

***

### **Grouping**

Extremely necessary for the activation of the rule. <mark style="color:green;">It determines which field is necessary for Inopli to use in the treatment process</mark>, usually the field identifying the origin of the attack, with the possibility of configuring one or more for each SIEM.

<figure><img src="/files/5PV4KucaJuBagI6phVPa" alt=""><figcaption><p>Grouping Stage</p></figcaption></figure>

***
