elastic / kibana

Your window into the Elastic Stack
https://www.elastic.co/products/kibana
Other
19.67k stars 8.23k forks source link

[Alerts] Add "Mark as Acknowledgement" to Observability Alerts #172877

Open Erikg346 opened 11 months ago

Erikg346 commented 11 months ago

Describe the feature: Currently, Security - Alerts has better alert statuses than Observability does. Security has "Marked as Acknowledged" and "Mark as Closed": image

Observability currently has "Mark as Untracked" only: image

Describe a specific use case for the feature: Our team using Observability would like to use at least "Mark as Acknowledged" to help with too many notifications from alerts. This is acknowledged-based throttling would help alleviate the spam.

elasticmachine commented 11 months ago

Pinging @elastic/obs-ux-management-team (Team:obs-ux-management)

elasticmachine commented 11 months ago

Pinging @elastic/response-ops (Team:ResponseOps)

elasticmachine commented 11 months ago

Pinging @elastic/unified-observability (Team:Observability)

cnasikas commented 11 months ago

cc @XavierM @shanisagiv1

vinaychandrasekhar commented 10 months ago

@XavierM @shanisagiv1 let's chat on this topic (we've discussed this previously). Thanks

shanisagiv1 commented 10 months ago

@vinaychandrasekhar what does Ack status mean for o11y users? Atm we have the life-cycled alerts mechanism so alerts will be Active or Recovered in the next rule monitoring. Also recently we added the "Untracked" for situations where we no longer want to track the state.

Does Ack is for taking ownership of the alerts? does it affect the triggered actions somehow?

@XavierM added this to the next Alerting weekly so we can make sure we're aligned on the behavior here. Thanks

carlosaya commented 7 months ago

following this. we are migrating from another tool and some of our teams are used to this type of functionality in competing products. It would definitely be beneficial to have this option in observability alerts.