-
Notifications
You must be signed in to change notification settings - Fork 8.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[RAC] Filter active/recovered status #108119
Comments
Pinging @elastic/logs-metrics-ui (Team:logs-metrics-ui) |
I checked current implementation and filter actions are being applied to all columns (whole row), whereas we would like to apply them only to one column, the status column. If we apply them to all columns, then I guess the reason field would be problematic, since it is not analyzed. @jasonrhodes who should I tag from security team to check if there is already a way to add filter actions per column? I am a bit blocked with broken environment. I can check it out further once my environment is up and running |
I think we need to proceed with applying this to all columns for now and we can circle back on whether it's possible (or useful, even) to have different hover actions per column/cell. The "reason" field won't be totally problematic in this case because it will filter for the exact reason, which will work since the field is a "keyword" field. It will have issues because some rule types are not indexing the reason, so those alerts will not show up even if their reason matches, but there's nothing we can do there for now. |
@jasonrhodes Ok agree. I need a clarification, the id we get from the status field at the moment is Regarding reason there are a couple of bugs at the moment. I am writing them down and we should handle them in another ticket:
|
ℹ️ To add some more context: Currently we have constants for both Regarding the reason field, I commented on your other issue. The question becomes whether we want the field to be a |
📝 Summary
In the Observability alerts table user should have the option to filter by the alert status(
kibana.alert.system_status
), which can be eitheractive
orrecovered
. This shouldn't be confused with the workflow status (kibana.alert.workflow_status) which can be open, acknowledged, closed✔️ Acceptance criteria
Depends on #108150
The text was updated successfully, but these errors were encountered: