Hi,
I was just creating a rule in LEM in which i want multiple events clubbed in, like an alert /rule will fire if three failed login attempts -two attempts from same user and one attempt from distinct user but source ip is same. now I am able to see the fired rule but all events are not collecting o=in a rule I mean I can see only rule not all the events like three user's attempt and their ip addresses.