I would like to suggest a small improvement to the Alert Rule import feature.
When importing an existing alert rule, some settings are already copied correctly, such as the main rule details, severity, max alerts, delay, interval, mute, recovery, and ack alert options.
However, I noticed that some other parts are not copied, for example:
-Advanced rule logic
-Match devices
-Match groups
-Match locations
-Transports
-Procedure URL
-Notes
It would be really helpful if the import function could copy everything from the original alert rule, so the imported rule starts as a full copy of the existing one.
This would make it easier and safer to reuse complex alert rules, especially when they have advanced logic, specific device/group/location matches, custom transports, notes, or procedure links. It would also help avoid missing something when recreating similar rules.