Skip to content

Conversation

nastasha-solomon
Copy link
Contributor

@nastasha-solomon nastasha-solomon commented Aug 27, 2025

NOTE TO SELF (09/10/25): Sync with @denar50 about feature flag when I'm back.

Contributes to #2526 by documenting the new securitySolution:suppressionBehaviorOnAlertClosure advanced setting. (preview)

Also made the following changes:

  • Moved pre-reqs for using alert suppression to the section that has instructions for using it. This placement seems more appropriate. Also made light revisions to wordy steps. (preview)
  • Moved that giant note about suppressing fields with multiple values to a dedicated section with the goal of streamlining the instructions for configuring suppression. (preview)
  • Added a new section that explained the impact of closing alerts that were generated by alert suppression. (preview)
  • Resized a few images that looked disproportionately large.

NOTE: Made the same content improvements to the 8.x suppression docs in elastic/security-docs#7083

@nastasha-solomon nastasha-solomon self-assigned this Aug 27, 2025
Copy link

github-actions bot commented Aug 27, 2025

@nastasha-solomon nastasha-solomon changed the title [Security][9.x & Serverless]: New advanced setting that allows the suppression window [Security][9.2 & Serverless]: New advanced setting that allows the suppression window Aug 29, 2025
Copy link
Contributor

@approksiu approksiu left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Awesome work!

@nastasha-solomon nastasha-solomon changed the title [Security][9.2 & Serverless]: New advanced setting that allows the suppression window [Security][9.2 & Serverless]: New advanced setting that controls suppression window behavior Sep 1, 2025
Copy link

@denar50 denar50 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@nastasha-solomon
Copy link
Contributor Author

Checked the Serverless prod project and verified the advanced setting was available. Merging PR now.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants