Is there a way to aggregate two or more capture (ingest) interfaces into a single interface in Security Analytics?
Yes, in some cases it is advantageous to aggregate two or more physical interfaces into one virtual interface. For example, if you have separate physical interfaces for Rx and Tx traffic -- an aggregated interface permits Security Analytics to match initiator traffic with its corresponding responder traffic.
For more information on capture interface aggregation and how to create one, see Capture-Interface Aggregation in the official documentation.