Alerts Dashboard Showing All Alerts when "Open" alerts are cleared

Hi All,

We recently upgraded to Kibana 8.8.0 from 8.0. When using the Alerts dashboard under Kibana Security, we typically use the status filter to filter the dashboard to show only "open" alerts, so that our analysts know what alerts need to be triaged (and have not been acknowledged/closed by other analysts). After upgrading, the alerts dashboard now displays all alerts when there are no more open alerts left. The status control has "open" listed as an ignored value.

It is confusing when you expect the dashboard to only show open alerts, and it ends up showing all alerts instead (because there are no open alerts left).

Is this a bug or expected behavior?

To recreate the issue, set the status on the alerts dashboard to "open," then close all of the alerts, and now the alerts dashboard will show all alerts instead of 0 open alerts. The "open"status filter does not function as expected.

The status control will also list "open" as being an ignored value.
open_ignored

I can confirm that we have the same experience when upgrading from 8.7.0 to 8.8.0, and I don't know if this is a bug or a "feature" according to Elastic but we find the new behaviour extremely counterproductive. I have a case on this with Elastic support but have so far not heard any useful feedback on it.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.