Whow acknowledged alert #15330
Unanswered
GyciakasGh0st
asked this question in
Ideas
Replies: 2 comments 2 replies
-
|
You would need to find the acknowleded event in the SOC logs and find the |
Beta Was this translation helpful? Give feedback.
2 replies
-
|
I've created a feature request to make this easier to lookup. We'll see about including it in an upcoming release. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
The indexes .ds-logs-detections.alerts-so*
Has field event.acknowledged it show if alert was acknowledged or not .
But we can't find which will show which user acknowledged Alert. Maybe where is seperate index for that ?
Beta Was this translation helpful? Give feedback.
All reactions