Environment
- EDR (formerly CB Response) Server: 6.1 and above (on-prem only)
Objective
Bulk delete alerts from the triage page
Resolution
Deleting alerts will permanently remove them from the system. Consider bulk resolving alerts through the UI or API if alert retention is desired
- Alerts can be removed via curl commands to Solr using the <delete> tags
Additional Notes
Example queries. Items in bold should be changed with desired field value
- Delete alerts from a specific feed
- Delete alerts from a specific watchlist
- Delete alerts with a specific status