Bug ID 672680: Alerts marked with "drop" status

Last Modified: Apr 10, 2019

Bug Tracker

Affected Product:  See more info
BIG-IQ Fraud Protection Service (FPS)(all modules)

Known Affected Versions:
5.2.0, 5.3.0

Fixed In:
5.4.0

Opened: Jul 06, 2017
Severity: 3-Major

Symptoms

BIG-IQ doesn't delete alerts with the drop status from its database when you apply transform rules.

Impact

This could cause the alert database to grow substantially, which could impact database capacity and product efficiency.

Conditions

If an existing alert status is changed to drop when new transform rules are applied to it, the alert incorrectly remains in the BIG-IQ alert list.

Workaround

To avoid this, you can manually delete the alerts with status of drop from the list of alerts.

Fix Information

This issue is resolved. BIG-IQ now properly deletes alerts with the status of drop.

Behavior Change