Skip to main content

Chronicle SIEM Dashboard

  • September 14, 2024
  • 2 replies
  • 26 views

Forum|alt.badge.img

I Want to create a dashboard for the alerts that are triggered in SIEM and need to know the case has been created in SOAR arent?
Dashboard to find when was the last alert created in SIEM, when was the last case created in SOAR, how many laerts got created and subsequent cases in SOAR

2 replies

vaskenh
Staff
Forum|alt.badge.img+13
  • Staff
  • September 16, 2024

Hi @KesavR.   Have you tried starting with any of the existing dashboards as a way to get ideas for how to put something like this together?

For example, the SecOps platform has distinct dashboards for things like rule detections as well as SOAR case creation like shown below.  You can use these dashboards as-is or use them as inspiration for creating your own under Personal Dashboard

Example of a dashboard showing case generation and associated priority.

Here is another dashboard that is centered around rule detections specifically (SIEM).

 

 


AymanC
Forum|alt.badge.img+13
  • Bronze 5
  • September 16, 2024

Do you have access to Advanced Reports? @KesavR