Alarming Disabled Rules Appearing in Alerts Console – Anyone Else?

 

Hey everyone!

I've come across a peculiar issue and wanted to see if anyone else is experiencing the same thing. Normally, I'd open a support case for this, but since we're not on GCP yet and the change to GCP is ongoing, I can't do that just yet. So, I'm crossing my fingers that someone from Google can either confirm they're working on this or, if it's a more widespread issue.

Here's what I've noticed:

  1. Alerts with alarming disabled are still showing up on the "Alerts & IOCs" page. We've seen this happening for both Curated Detections and Custom Rules. To catch our breath, we've gone ahead and archived the rules and disabled them completely.
  2. To add to the strangeness, we can't close these alerts either.

Anyone else dealing with this? 

 

Edit: Seems like this issue was fixed! Thanks Everyone!

0 3 219
3 REPLIES 3

This has also been observed by myself, and have raised a support case, so definitely not only happening within your instance!

I see this, too. It looks like it might have been a temporary burst that stopped around 16:41Z, though.

Within our instance we have received confirmation from Google Cloud support that this issue should now be rectified.