'Kibana Alerts aknowlidge-store-delete

Could you please help me with alerts in Kibana coming from Wazuh as FIM? I am successfully getting alerts from wazuh agents and showing it in Agent events.

But I am able only to check the alert. There is no button to aknowledge or delete seen alert. As I am new in wazuh monitoring, could you please let me know, how can I store or set aletrs as completed?

Thank you.



Solution 1:[1]

The problem is that the alerts are indexed and you can't remove them(you can remove the index). The alerts' purpose is not to be deleted, the alerts allow you to have an "activity history". I think it is good to have all the alerts during the time, even if you have solved or checked that alert.

Sources

This article follows the attribution requirements of Stack Overflow and is licensed under CC BY-SA 3.0.

Source: Stack Overflow

Solution Source
Solution 1 roronoasins