"Force Close" Option for False Positive Alerts
needs review
m
mplummer@bostonnetworks.com
Please give administrators a way to close an alert while making sure it does not re-open for this specific instance without having to wait 7 days or silence it.Best way for me to explain this is probably through an example:A client of ours had a legitimate A record change to their domain's DNS, but every time we try to close the ticket, it just gets re-opened. Support informed me that the only way to avoid these tickets from getting re-opened is to change the record back to the original value, edit the alert to not detect this change any further, or to wait 7 days before closing it.This seems like a bit of an oversight, administrators should be able to have a status which tells LG that an alert was the result of a false positive and to recognize it as legitimate.