[Security Solution] Redundant Warning Messages in Rule Preview When Exceeding Alert Limit
#211821 opened on Feb 19, 2025
Description
Description:
When a user enters a query in Rule Preview that generates more alerts than the maximum allowed, a general warning message is correctly displayed stating that some alerts were not created. However, instead of a single warning, multiple redundant warning messages appear, each displaying the same information.
Kibana/Elasticsearch Stack version:
8.18 BC4
Functional Area (e.g. Endpoint management, timelines, resolver, etc.):
Detection Rules Preview
Steps to reproduce:
- Navigate to Detection Rules and create/edit a rule.
- Enter a query that is expected to generate a high number of alerts exceeding the maximum alert limit.
- Click Rule Preview to preview the alerts.
- Observe that multiple identical warning messages appear, instead of a single consolidated message.
Current behavior:
The UI shows multiple redundant warning messages, all conveying the same information.
Expected behavior:
A single warning message should be displayed to inform the user that the maximum alert limit has been reached, preventing unnecessary redundancy.
Screenshots:
https://github.com/user-attachments/assets/331e0c58-ae14-483d-a0a7-7840adacd7e4