Skip to content

[BUG] Alert details flyout shows all the findings from the detector containing the alert trigger condition #228

Closed
@amsiglan

Description

@amsiglan

What is the bug?
In the alert details flyout, findings that caused the alert are shown. However, the table lists all the findings (even ones that are not related to the current alert) generated by the detector that has the alert's trigger condition.

How can one reproduce the bug?
Steps to reproduce the behavior:

  1. Create a detector with an alert condition and execution frequency of 1 min.
  2. Ingest multiple logs matching the detector configuration such that the finding would result in an alert
  3. Wait for the findings and alerts to be generated
    1. Once alerts come in, open one of the alert details, you will see multiple findings listed in the Findings table.

What is the expected behavior?
Only one finding should be listed in the table, since only that finding is related to the generated alert

What is your host/environment?
NA

Do you have any screenshots?

Do you have any additional context?
Add any other context about the problem.

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions