-
Notifications
You must be signed in to change notification settings - Fork 194
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Snoozing alert notifications for detection rules #3146
Comments
Hey, @maximpn! @e40pud and I had a quick convo this morning and Zhenia brought up some information that I think would be useful to include in the action snoozing docs:
I can insert this information as a note to the new Snooze rule actions section, the docs for upgrading from a 7.x version, and possibly call it out in the release notes/release highlight docs. What do you think? |
One more quick question: what, if any, changes were introduced to the publicly available Security rule APIs? Can users snooze rule actions via the Update rule API or any other detection APIs? |
This was addressed by elastic/kibana#156593. This way all the security rules will be migrated and unmuted.
We don't have any API in Security Solution related to snoozing. Everything is handled by Alerting API. |
Description
In 8.8, you can temporarily mute notifications created by rule actions. You can snooze rules from the following areas:
Rules table
Users click on the bell icon in the Notify column. When you click the button, you'll be offered additional customization options for the snoozle sesh.
To unsnooze the rule, can click the red icon.
Actions tab when editing a rule
Rule details page
Related:
Questions/tests to run
Doc updates
Notes
The text was updated successfully, but these errors were encountered: