# Identifying User Who Acknowledged Security Alerts

**URL:** https://discuss.elastic.co/t/identifying-user-who-acknowledged-security-alerts/363448
**Category:** Elastic Security
**Created:** [July 19, 2024, 4:33pm UTC](https://discuss.elastic.co/t/identifying-user-who-acknowledged-security-alerts/363448 "2024-07-19T16:33:53Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![ej210](https://avatars.discourse-cdn.com/v4/letter/e/f17d59/32.png) [@ej210](https://discuss.elastic.co/u/ej210)
#### Post date: [July 19, 2024, 4:33pm UTC](https://discuss.elastic.co/t/identifying-user-who-acknowledged-security-alerts/363448/1 "2024-07-19T16:33:53Z")

</div>

Hello, I have not been able to find any documentation or threads but apparently there might be a way to track who acknowledged alerts within Kibana Security, it appears the field "kibana.alert.workflow\_assignment\_ids" contains per docs "List of users assigned to an alert.

An array of unique identifiers (UIDs) for user profiles, for example: ["u\_1-0CcWliOCQ9T2MrK5YDjhpxZ\_AcxPKt3pwaICcnAUY\_0, u\_2-0CcWliOCQ9T2MrK5YDjhpxZ\_AcxPKt3pwaICcnAUY\_1"]

UIDs are linked to user profiles that are automatically created when users first log into a deployment. These profiles contain names, emails, profile avatars, and other user settings.".

How do you determine using that UID who exactly the user is though? Thanks for any assistance!

---

<div class="post-metadata">

### Author: ![isorokopud](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/isorokopud/32/119989_2.png) [@isorokopud](https://discuss.elastic.co/u/isorokopud)
#### Post date: [July 22, 2024, 10:45am UTC](https://discuss.elastic.co/t/identifying-user-who-acknowledged-security-alerts/363448/2 "2024-07-22T10:45:14Z")

</div>

Hey @ej210!

If you wanna track who updated alert's status you should use `kibana.alert.workflow_user` field instead. The `kibana.alert.workflow_assignment_ids` field is used for tracking users assigned to the alert. Also, `kibana.alert.workflow_status_updated_at` will show the time when the status was last updated.

To fetch user profile details having a UUID, you can use [these APIs](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-get-user-profile.html).

Let us know if that helps!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [August 19, 2024, 10:45am UTC](https://discuss.elastic.co/t/identifying-user-who-acknowledged-security-alerts/363448/3 "2024-08-19T10:45:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
