Closed dracon80 closed 5 days ago
What version of OpenCTI are you running? I have never seen this. Incidents' uniqueness are based on the incident name and timestamp of last sighting. Are you absolutely sure that your incident is not caused by a new alert, modifying the "last seen" property of the sighting? If so, would you mind trying another OpenCTI version? That project moves fast and breaks a lot of things.
I'm going to close this due to lack of activity, but by all means feel free to re-open. If so, please help me investigating the issue by providing some details about your alerts and your environment.
I'm running release 0.3.0 of the connector.
Manually running an enrichment on an indicator will create a new incident each time you run it, causing multiple incidents with the exact same details.