Skip to content

SOC AI not closing alerts #2044

@jay-oconnor

Description

@jay-oconnor

Acknowledgements

Describe the bug

Since the 11.2.7 release SOC AI rarely closes alerts. Instead, it's adding a comment similar to "The user admin changed alert status from Open to Completed " to the alert history, but leaving the alert open.

Regression Issue

  • Select this option if this issue appears to be a regression.

Expected Behavior

Expected behavior is for the alert status to be changed to completed.

Current Behavior

The alert status remains open, and a note stating it was marked as completed is added to alert history.

Reproduction Steps

Run UTMStack with the SOC AI feature enabled.

Possible Solution

This could be solved by reverting to previous release behavior.

Additional Information/Context

No response

UTMStack Version

11.2.7

Operating System and version

Ubuntu 24.04.3

Hypervisor and Version | Server Vendor and Model

XCP-NG | Dell PowerEdge R740

Browser and version

MS Edge147.0.3912.72

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions