Skip to main content
Question

correlation of the detection table, case and case_history

  • July 30, 2026
  • 3 replies
  • 99 views

hliu
Forum|alt.badge.img+6

It is fantastic that Secops is now offering the capability to search detections and cases in the SIEM.


But unfortunately today they are not able to be joined.

 

The prebuilt Detection > Alerts & IOCs dashboard is not enough to cover below cases.
 

Customers are expecting the SIEM to be able to correlate its own data, instead of relying on the usual external workaround culture to fill the gap.
 

Example use cases to cover:

  • Monitoring / dashboarding / detection of SIEM alerts that didn't open any SOAR case, because the connector crashed.
    Requiring to be able to left outer join the detection table with the case table, not possible today.


Please Google PM team take into consideration these feature requests.

Bonus bug: the detection.case_name is always empty even tho the case is created in the SOAR.

3 replies

cmorris
Staff
Forum|alt.badge.img+16
  • Staff
  • July 30, 2026

I noticed this as well recently and filed feature request # 540805241 for this to be added.


AymanC
Forum|alt.badge.img+14
  • Bronze 5
  • August 12, 2026

Hi ​@hliu,

 

I definitely agree there are some platform limitations.

For the MTTR and MTTA query, does this help - 🚀 Unlock Advanced SOC Metrics: Joining case and case_history in Native Dashboards | Community

Kind Regards,

Ayman


hliu
Forum|alt.badge.img+6
  • Author
  • Bronze 4
  • August 12, 2026

Yeah I saw that and if we follow it step by step, it actually doesn’t work… 😆

Whether it’s a bug or feature, appreciate ​@cmorris on raising it internally ❤️