Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[FEATURE] Alert acknowledgement, visible alert ID and acknowledgement notes #1500

Open
tomuk5 opened this issue Oct 25, 2023 · 2 comments
Open
Labels
enhancement New feature or request

Comments

@tomuk5
Copy link

tomuk5 commented Oct 25, 2023

Currently with alerts there is no ability to record or show who acknowledged an alert, reference an alert with a unique ID or make notes on an alert.

When acknowledging an alert, the username of the person acknowledging the alert should be recorded and be able to be viewed for all alerts that are already acknowledged.
Optionally, a notes field can be provided for the user acknowledging an alert to enter information regarding their investigation of the alert, incident number/etc.

There is currently no means to find out who acknowledged an alert and no ability to view the alert unique ID in the web interface (although it is available via the api GET /_plugins/_security_analytics/alerts?detectorType={type} under field alerts.id)

@tomuk5 tomuk5 added enhancement New feature or request untriaged labels Oct 25, 2023
@praveensameneni
Copy link
Member

Added to backlog

@praveensameneni
Copy link
Member

We plan to add some of the enhancements on alerting in 2.15 release.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants