Skip to content

Commit 9d4209c

Browse files
[Enhancement][ESS] Only open or acknowledged alerts are considered for alert suppression (#5122)
* First draft * Update docs/detections/alert-suppression.asciidoc
1 parent 9bb14b7 commit 9d4209c

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

docs/detections/alert-suppression.asciidoc

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -81,6 +81,8 @@ NOTE: These options are not available for threshold rules.
8181

8282
The {security-app} displays several indicators of whether a detection alert was created with alert suppression enabled, and how many duplicate alerts were suppressed.
8383

84+
IMPORTANT: After an alert is moved to the `Closed` status, it will no longer suppress new alerts. To prevent interruptions or unexpected changes in suppression, avoid closing alerts before the suppression interval ends.
85+
8486
* *Alerts* table — Icon in the *Rule* column. Hover to display the number of suppressed alerts:
8587
+
8688
[role="screenshot"]

0 commit comments

Comments
 (0)