Currently, the Wazuh Dashboard does not provide built-in options to mark alerts as closed, open, or cancelled. This is because the Wazuh Dashboard is a fork of OpenSearch Dashboards.
However, I came across a public third-party GitHub repository that provides a plugin for this functionality. It appears to have been tested with Wazuh versions 4.12 and 4.13.
You can try using this plugin with your Wazuh setup from the following link:
https://github.com/xrisbarney/Wazuh-alert-manager
Before making any changes to your existing environment, please ensure you take a snapshot or backup.
Wazuh is capable of integrating with any software using Wazuh's integrator module. Therefore, you can incorporate Wazuh with the case management, in that way you can achive this.
For example, we have a blog post to forward Wazuh alerts to the DFIR IRIS case management. Please check this post to have more details of how it can be achieved.
Feel free to let me know if you need any more help with this.
It appears that the plugin is not compatible with Wazuh 4.14. This is because Wazuh 4.14 uses OpenSearch 2.19.3, whereas Wazuh 4.13 uses OpenSearch 2.19.2.
As a result, the installation instructions for 4.13 cannot be applied to 4.14. We will need to wait until the plugin author releases an updated version that is compatible with Wazuh 4.14.x.
Apart from that, you can depend on the third-party case management tool as I mentioned above.
Let me know if you need further assistance on this.