Skip to content

Add alert triage suppression context gates#2592

Open
Errordog2 wants to merge 1 commit into
UnitOneAI:mainfrom
Errordog2:improve/alert-triage-suppression-context
Open

Add alert triage suppression context gates#2592
Errordog2 wants to merge 1 commit into
UnitOneAI:mainfrom
Errordog2:improve/alert-triage-suppression-context

Conversation

@Errordog2

Copy link
Copy Markdown

Summary

  • Adds a suppression and stale-context confidence gate to alert-triage.
  • Requires raw event count, unique entities, first/last-seen windows, suppression owner/expiry/approval, and asset/identity enrichment freshness before downgrading or closing grouped alerts.
  • Adds queue saturation and uncertainty escalation guidance, plus output fields for suppression/context confidence.

Addresses #2547.

Validation

  • git diff --check
  • Markdown fence balance check
  • Targeted marker check for v1.0.1, suppression/deduplication evidence, context freshness, queue saturation, and output fields

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant