-
Notifications
You must be signed in to change notification settings - Fork 640
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bulk Merge Alerts into Case #271
Comments
Hi @BrevilleBro. Thank you for this feature request. We had it in mind for quite sometime but we failed to create the corresponding issue. Indeed, merging multiple alerts into a case (for example alerts stemming from a spamrun where users would report emails related to the same campaign) makes a lot of sense. We will try to implement it in Cerana (3.x). |
+1 That would be indeed very useful for spam/phishing cases |
+1 I have just begun using TheHive and this was the first thing I thought of as I began acclimating myself with the software. It would be amazing if I had a quicker way to go through the alerts and group them into a single case. It would also be great to have something like the alert view in the case itself so I can have a pretty list of the alerts that were imported into the case and then I can expand them if I need be. |
Having the same ability to merge multiple cases would be also really helpful |
Would also be great if case were actually merged and not creating a new case of the two you merge. |
+1 for "bulk alert to case" merge my current thehive version is 3.0.6 |
Good afternoon! |
Hello! |
This would be life changing. We currently open distinct cases and then merge, and since you can't bulk merge cases, it's all very tedious. |
We will implement it in 3.3.0 (planned end of Jan). You will be able to select multiple alerts at once and create a single case out of them or merge them into an existing case using its ID. |
Hi team, I found this issue is similar to my use case, If multiple alerts received for the same event type from any siem, instead of creating a new case, it should update the existing case with the count of alerts, am using thehive 5. Is there any way for this, kindly let me know if any pointers or references for the same. Thanks in advance... |
Bulk Merge Alerts into Case
Request Type
Feature Request
Problem Description
Sometimes we get a large number of alerts, with only slightly varying information (maybe MD5 is different between the alerts), however, they all still relate to the same case. It would be great to have a bulk merge alert (like we have bulk mark as read) to capture all the slightly varying observables into a single case easily.
This feature should allow:
The text was updated successfully, but these errors were encountered: