Skip to content

Commit 30e85a2

Browse files
[8.9] [Enhancement][ESS] Only open or acknowledged alerts are considered for alert suppression (backport #5122) (#5244)
* First draft * Update docs/detections/alert-suppression.asciidoc (cherry picked from commit 9d4209c) Co-authored-by: Nastasha Solomon <[email protected]>
1 parent e22eb6e commit 30e85a2

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

docs/detections/alert-suppression.asciidoc

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -47,6 +47,8 @@ TIP: Use the *Rule preview* before saving the rule to visualize how alert suppre
4747

4848
The {security-app} displays several indicators of whether a detection alert was created with alert suppression enabled, and how many duplicate alerts were suppressed.
4949

50+
IMPORTANT: After an alert is moved to the `Closed` status, it will no longer suppress new alerts. To prevent interruptions or unexpected changes in suppression, avoid closing alerts before the suppression interval ends.
51+
5052
* *Alerts* table — Icon in the *Rule* column. Hover to display the number of suppressed alerts:
5153
+
5254
[role="screenshot"]

0 commit comments

Comments
 (0)