Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Kibana Security Alerts - Assigning multiple (>100) alerts to a user at once #183889

Open
willem-dhaese opened this issue May 21, 2024 · 5 comments
Assignees
Labels
Team:Detection Engine Security Solution Detection Engine Area Team:Detections and Resp Security Detection Response Team

Comments

@willem-dhaese
Copy link

See https://discuss.elastic.co/t/alert-triage-enhancement-ideas/359602

Currently, we can't assign more than 100 alerts to a user at a time. When we click "Select all alerts," the "assign to user" option gets greyed out. This can be a bit frustrating when dealing with a large number of alerts. It would be great if this limit could be increased or removed altogether.

image

@yctercero @Kseniiaign

"Team:Detection Engine"
"Team:Detections and Resp"

@botelastic botelastic bot added the needs-team Issues missing a team label label May 21, 2024
@approksiu approksiu added the Team:Detection Engine Security Solution Detection Engine Area label May 21, 2024
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-detection-engine (Team:Detection Engine)

@botelastic botelastic bot removed the needs-team Issues missing a team label label May 21, 2024
@willem-dhaese
Copy link
Author

Nice to meet you in GH @approksiu 😃
It was with you I had a drink in Prague together with @MikePaquette right?

@approksiu approksiu added the Team:Detections and Resp Security Detection Response Team label May 21, 2024
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-detections-response (Team:Detections and Resp)

@yctercero
Copy link
Contributor

@approksiu this is a UI limitation we have for all bulk actions where we limit the number to however many rules are being shown (so say you select to show 5, 25, or 100) rules per page, that's what the max will be. We prevent bulk actions when a user selects Select all on rules which could number 1000+.

@elastic/security-detection-rule-management have there been any considerations to increase the limit?

@willem-dhaese confirmed with @e40pud that this limitation does not exist on the API.

@willemdh
Copy link

Maybe adding a 250 select option is doable?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Team:Detection Engine Security Solution Detection Engine Area Team:Detections and Resp Security Detection Response Team
Projects
None yet
Development

No branches or pull requests

5 participants