# Alerting during Penetration tests?

**URL:** <https://discuss.elastic.co/t/alerting-during-penetration-tests/384718>\
**Category:** Elastic Security\
**Created:** [January 23, 2026, 2:28pm UTC](https://discuss.elastic.co/t/alerting-during-penetration-tests/384718 "2026-01-23T14:28:31Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gloom](https://avatars.discourse-cdn.com/v4/letter/g/278dde/32.png) [@Gloom](https://discuss.elastic.co/u/Gloom)\
**Post date:** [January 23, 2026, 2:28pm UTC](https://discuss.elastic.co/t/alerting-during-penetration-tests/384718/1 "2026-01-23T14:28:31Z")

</div>

Is there anyway for all alerts generated by a list of hosts / ips / users to all be added to one case automatically? The idea being that during a pentest we don’t want to have to triage the alerts at that time, but don’t want to disabled them as we want to see what would have been caught.
