Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Response Ops][Alerting] Alerts as data aliases should be hidden #178589

Open
ymao1 opened this issue Mar 12, 2024 · 2 comments
Open

[Response Ops][Alerting] Alerts as data aliases should be hidden #178589

ymao1 opened this issue Mar 12, 2024 · 2 comments
Labels
Feature:Alerting/Alerts-as-Data Issues related to Alerts-as-data and RuleRegistry Feature:Alerting Team:ResponseOps Label for the ResponseOps team (formerly the Cases and Alerting teams)

Comments

@ymao1
Copy link
Contributor

ymao1 commented Mar 12, 2024

Alerts as data indices are created as hidden but their aliases are not, leading to some inconsistencies. We should be able to create new aliases as hidden by setting is_hidden: true here but we should also add a call to update existing aliases to hidden during resource installation.

@ymao1 ymao1 added Feature:Alerting Team:ResponseOps Label for the ResponseOps team (formerly the Cases and Alerting teams) Feature:Alerting/Alerts-as-Data Issues related to Alerts-as-data and RuleRegistry labels Mar 12, 2024
@elasticmachine
Copy link
Contributor

Pinging @elastic/response-ops (Team:ResponseOps)

@pmuellr
Copy link
Member

pmuellr commented Mar 13, 2024

Remembering when we did something very similar for the event log - one issue we had was that the additional processing could take a while, and encounter errors. Can't remember if we made initialization wait through these modifications, and what we do with errors - beyond ignoring them (more or less ... there's not much we can do). I'm thinking we even stopped logging them because they were noisy.

Looking through the event log PRs, this one looks particularly relevant: #122882

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Feature:Alerting/Alerts-as-Data Issues related to Alerts-as-data and RuleRegistry Feature:Alerting Team:ResponseOps Label for the ResponseOps team (formerly the Cases and Alerting teams)
Projects
None yet
Development

No branches or pull requests

3 participants