Skip to main content
Question

correlation of the detection table, case and case_history

  • July 30, 2026
  • 1 reply
  • 34 views

hliu
Forum|alt.badge.img+5

It is fantastic that Secops is now offering the capability to search detections and cases in the SIEM.


But unfortunately today they are not able to be joined.

 

The prebuilt Detection > Alerts & IOCs dashboard is not enough to cover below cases.
 

Customers are expecting the SIEM to be able to correlate its own data, instead of relying on the usual external workaround culture to fill the gap.
 

Example use cases to cover:

  • Monitoring / dashboarding / detection of SIEM alerts that didn't open any SOAR case, because the connector crashed.
    Requiring to be able to left outer join the detection table with the case table, not possible today.


Please Google PM team take into consideration these feature requests.

Bonus bug: the detection.case_name is always empty even tho the case is created in the SOAR.

1 reply

cmorris
Staff
Forum|alt.badge.img+16
  • Staff
  • July 30, 2026

I noticed this as well recently and filed feature request # 540805241 for this to be added.