Skip to content

Commit 8c8b7b4

Browse files
[8.12] [Enhancement][ESS] Only open or acknowledged alerts are considered for alert suppression (backport #5122) (#5241)
* First draft * Update docs/detections/alert-suppression.asciidoc (cherry picked from commit 9d4209c) Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com>
1 parent b544732 commit 8c8b7b4

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

docs/detections/alert-suppression.asciidoc

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -56,6 +56,8 @@ TIP: Use the *Rule preview* before saving the rule to visualize how alert suppre
5656

5757
The {security-app} displays several indicators of whether a detection alert was created with alert suppression enabled, and how many duplicate alerts were suppressed.
5858

59+
IMPORTANT: After an alert is moved to the `Closed` status, it will no longer suppress new alerts. To prevent interruptions or unexpected changes in suppression, avoid closing alerts before the suppression interval ends.
60+
5961
* *Alerts* table — Icon in the *Rule* column. Hover to display the number of suppressed alerts:
6062
+
6163
[role="screenshot"]

0 commit comments

Comments
 (0)