# Alert response/action SLA support?

**URL:** <https://discuss.elastic.co/t/alert-response-action-sla-support/379333>\
**Category:** Elastic Security\
**Created:** [June 19, 2025, 2:56pm UTC](https://discuss.elastic.co/t/alert-response-action-sla-support/379333 "2025-06-19T14:56:07Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![taylor.callow](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/taylor.callow/32/143756_2.png) [@taylor.callow](https://discuss.elastic.co/u/taylor.callow)\
**Post date:** [June 19, 2025, 2:56pm UTC](https://discuss.elastic.co/t/alert-response-action-sla-support/379333/1 "2025-06-19T14:56:07Z")

</div>

Hey all,

I cant see any built-in function to view/report on values like response time (e.g. time between alert being generated and time alert is set to acknowledged/closed).

I can see that alerts appear to have a signal.last.updated value but this does not differentiate between acknowledged/closed, and can of course be changed later if the case is reopened etc.

Ideally what I was hoping for was somewhere to pull the data on:

timestamp alert is generated  
timestamp alert is set to acknowledged  
timestamp alert is set to closed

Am I missing something or is this just not something that is logged currently in Elastic Security?

Thanks!

Taylor
