Skip to content

Commit e6b3f75

Browse files
nastasha-solomonmergify[bot]
authored andcommitted
[Enhancement][ESS] Only open or acknowledged alerts are considered for alert suppression (#5122)
* First draft * Update docs/detections/alert-suppression.asciidoc (cherry picked from commit 9d4209c)
1 parent 48b778b commit e6b3f75

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

docs/detections/alert-suppression.asciidoc

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -43,6 +43,8 @@ TIP: Use the *Rule preview* before saving the rule to visualize how alert suppre
4343

4444
The {security-app} displays several indicators of whether a detection alert was created with alert suppression enabled, and how many duplicate alerts were suppressed.
4545

46+
IMPORTANT: After an alert is moved to the `Closed` status, it will no longer suppress new alerts. To prevent interruptions or unexpected changes in suppression, avoid closing alerts before the suppression interval ends.
47+
4648
* *Alerts* table — Icon in the *Rule* column. Hover to display the number of suppressed alerts:
4749
+
4850
[role="screenshot"]

0 commit comments

Comments
 (0)