Skip to main content
Solved

Case Merge

  • December 5, 2024
  • 3 replies
  • 106 views

yasinmnk
Forum|alt.badge.img+7

Hi
Our customer receive several cases and would like to prevent duplicates and merge cases for a better overview! Is that possible ? if yes,  how and is there any documentation or guide for that thanks in advance for answers!

Best answer by kentphelps

Merge is available on the Search Screen Let us know if that does not help here.

3 replies

kentphelps
Staff
Forum|alt.badge.img+11
  • Staff
  • Answer
  • December 5, 2024

Merge is available on the Search Screen Let us know if that does not help here.


AymanC
Forum|alt.badge.img+13
  • Bronze 5
  • December 5, 2024

hi @yasinmnk,

You can also look into alert grouping - so it identifies similar alerts (specified by your own conditions) within a specified time period, and will group these alerts into one case. Alternatively, another way to look into this which hypothetically sounds possible is by creating a playbook that gets attached to these specific cases, using the 'Get Similar Cases' action within the playbook, attach this as the first step, if there's a xxx% match (for example 100% entity match), along with the same/similar case name, to automatically close the case.

Reference: https://cloud.google.com/chronicle/docs/soar/investigate/working-with-alerts/alert-grouping-mechanism-admin

Kind Regards,

Ayman


yasinmnk
Forum|alt.badge.img+7
  • Author
  • Bronze 3
  • December 6, 2024

hi @yasinmnk,

You can also look into alert grouping - so it identifies similar alerts (specified by your own conditions) within a specified time period, and will group these alerts into one case. Alternatively, another way to look into this which hypothetically sounds possible is by creating a playbook that gets attached to these specific cases, using the 'Get Similar Cases' action within the playbook, attach this as the first step, if there's a xxx% match (for example 100% entity match), along with the same/similar case name, to automatically close the case.

Reference: https://cloud.google.com/chronicle/docs/soar/investigate/working-with-alerts/alert-grouping-mechanism-admin

Kind Regards,

Ayman


Hi @AymanC  Thanks so much for your answer, was very helpful:
Best Regards,
Yasin