Skip to content

Commit 3ab6527

Browse files
[8.7] [Enhancement][ESS] Only open or acknowledged alerts are considered for alert suppression (backport #5122) (#5246)
* First draft * Update docs/detections/alert-suppression.asciidoc (cherry picked from commit 9d4209c) Co-authored-by: Nastasha Solomon <[email protected]>
1 parent 48b778b commit 3ab6527

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

docs/detections/alert-suppression.asciidoc

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -43,6 +43,8 @@ TIP: Use the *Rule preview* before saving the rule to visualize how alert suppre
4343

4444
The {security-app} displays several indicators of whether a detection alert was created with alert suppression enabled, and how many duplicate alerts were suppressed.
4545

46+
IMPORTANT: After an alert is moved to the `Closed` status, it will no longer suppress new alerts. To prevent interruptions or unexpected changes in suppression, avoid closing alerts before the suppression interval ends.
47+
4648
* *Alerts* table — Icon in the *Rule* column. Hover to display the number of suppressed alerts:
4749
+
4850
[role="screenshot"]

0 commit comments

Comments
 (0)