Skip to content
Discussion options

You must be logged in to vote

Are you in the Ungrouped view perhaps? The default view in Alerts should group by rule name, so if you have hundreds or thousands of the same alert, it should just be one row with the total number in the Count column. You should then be able to acknowledge all of those at one time. For more information, please see https://docs.securityonion.net/en/2.3/alerts.html.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by dougburks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Ideas
Labels
None yet
2 participants