Skip to content

[BUG] Threat Alerts page shows single detector results instead of aggregate #1549

Description

@engechas

What is the bug?
A clear and concise description of the bug.

The Threat Alerts page scopes itself to a single detector, showing only that detector's alerts. This appears to be triggered by navigating from a detector edit/save flow, and the scoped state persists even after navigating away and back to the page.

How can one reproduce the bug?
Steps to reproduce the behavior:

  1. Navigate to the Threat Alerts page (/app/threat_alerts)
  2. Observe that only alerts from one detector are visible
  3. Navigate to a different detector, edit the trigger name (even making no real change — delete and re-select the same name), and save
  4. Navigate back to Threat Alerts — the page now exclusively shows alerts from the detector that was just edited

What is the expected behavior?
A clear and concise description of what you expected to happen.

The Threat Alerts page should display alerts from all active detectors in an aggregated view, similar to how the Findings tab works — which correctly shows findings across all detectors.

What is your host/environment?

  • OS: [e.g. iOS]
  • Version [e.g. 22]
  • Plugins

Do you have any screenshots?
If applicable, add screenshots to help explain your problem.

Do you have any additional context?
Add any other context about the problem.

Note: Remember to sanitize/redact any sensitive fields or values

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions