It is fantastic that Secops is now offering the capability to search detections and cases in the SIEM.
But unfortunately today they are not able to be joined.
The prebuilt Detection > Alerts & IOCs dashboard is not enough to cover below cases.
Customers are expecting the SIEM to be able to correlate its own data, instead of relying on the usual external workaround culture to fill the gap.
Example use cases to cover:
- MTTA and MTTR calculations, described here by another member.
- Monitoring / dashboarding / detection of SIEM alerts that didn't open any SOAR case, because the connector crashed.
Requiring to be able to left outer join the detection table with the case table, not possible today.
Please Google PM team take into consideration these feature requests.
Bonus bug: the detection.case_name is always empty even tho the case is created in the SOAR.

