Summarization Versus Snoozing
Summarization of alerts applies to all hosts based on the alert configuration, while snoozing applies to a specific alert.
Here're a few differences between the two:
-
For example, compliance configuration depends on the application workspace, and the type of violation an alert should be generated for. Thus, summarization is applicable to all the hosts based on an alert rule, for example an escaped condition, while snoozingis applicable to a very specfic consumer scope, provider scope, provider port, protocol, and escaped condition.
-
A summary alert is generated at the specified frequency with the alerts that are generated within that interval. Summary alerts provide a count of the number of alerts triggered within the specified frequency interval, along with a summarization of all the agents in that scope.
-
Snoozing alert only results in an alert being sent when a new alert is generated after the snooze interval has passed. Additionally, a platform alert that is configured on a path between source scope and destination scope with a hop count less than some amount, will generate a very specific alert.