Hi kadd,
Apologies for the late response, please let me clarify how <group> information can help route the events to other pre-existing rules with <if_group> but in this particular case, it wouldn't change the behavior.
Also, the <group> tags will also provide regulatory compliance mapping as well as further context on the type of alert
I hope this helps.
Best Regards,
Adebayo Kalejaiye