| Description | Alerts may be observed to have different “Event Details” when viewed in the platform at different time points. This can also occur when comparing the current Event Details in the console with the details received for that alert via an Alert Channel notification (such as email or JIRA). |
| Scope | Lacework Console, Lacework Alert Channel integrations. |
| Solution |
This behaviour is a benign side effect of a new feature providing near-to-real-time alerting. A key component of near-to-real-time alerting is that for up to an hour after the alert was generated, certain alert types can be appended with newly relevant event data.
This in turn can cause the values in the Alert summary fields to appear to have changed. Any notification that was sent to a configured Alert Channel would still show the original summary data in the “Event Details”.
Example:
Alert Notification received in Slack about IP 71.6.146.186
However, after opening the Alert in the Lacework console a different IP 43.134.227.248 is highlighted
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.