We’ve recently purchased SecOps SOAR capabilities while the SecOps SIEM is in place for more than 2 years.
We have custom rules and also the alerting is available. But no cases are being created in SOAR.
I could see the Google Chronicle is configured. Would lile to know if I’m missing something here, since I’m new to SOAR and SecOps SOAR as well.
Question
Chronicle SecOps SIEM and SOAR
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
