You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
If you import an alert to case that has observables, these observables are merged into the case.
If the observables already exist they are not created.
But if the alert observables have tags set that are not present at the case-observables they are not added.
Possible Solutions
If an imported alert observable already exists in the case, add the missing tags to the case observable.
The text was updated successfully, but these errors were encountered:
This will be very helpful. I confirmed that 3.4.0-RC1 or older versions do not add the tags from an Alert when merging into a Case. It does not matter if the case does or does not have tags, they do not get added.
Having this functionality will give analysts at least two great capabilities which are: using responders that rely on tags that have been created on the initial alert and filtering on cases that have tags that were created at alert time.
Thanks for adding this to the list! I look forward to testing/implementing!
Request Type
Feature Request
Work Environment
Problem Description
If you import an alert to case that has observables, these observables are merged into the case.
If the observables already exist they are not created.
But if the alert observables have tags set that are not present at the case-observables they are not added.
Possible Solutions
If an imported alert observable already exists in the case, add the missing tags to the case observable.
The text was updated successfully, but these errors were encountered: