Include alert mute state and reason when persisting triggered alerts #178889
Labels
Feature:Alerting/Alerts-as-Data
Issues related to Alerts-as-data and RuleRegistry
Feature:Alerting
Team:ResponseOps
Label for the ResponseOps team (formerly the Cases and Alerting teams)
Describe the feature:
For reporting purposes, it would be highly beneficial to have the capability to filter out muted alerts—those which did not trigger any actions.
The current data structure within the
.alerts-stack.alerts-default
index lacks information about whether an alert was in a muted state at the time it was triggered. Therefore, a feature enhancement is requested to persist information regarding the alert's state upon triggering.Additionally, introducing fields that detail the reasons why an alert did not run its actions, such as being in a muted state for various reasons, would also be helpful.
Describe a specific use case for the feature:
The primary use case for this request stems from the need for more precise and effective reporting capabilities with regards to alerting. Being able to distinguish between alerts that were actively suppressed and those that triggered actions allows for a more accurate assessment of alert "noise".
The text was updated successfully, but these errors were encountered: