Hi Guys,
I have encountered an issue:
A Sentinel Incident was triggered without any associated event. Consequently, a SOAR case was created for this incident, but with 1 hour delay without any alert event.
Does anyone knows case of this issue?
Hi Guys,
I have encountered an issue:
A Sentinel Incident was triggered without any associated event. Consequently, a SOAR case was created for this incident, but with 1 hour delay without any alert event.
Does anyone knows case of this issue?
Best answer by Dmitry_Sarakeev
hi @VictorSOAR , please either create a gcp support ticket or enable connector log collection with the most detailed level (info) and try to repro the issue and see if there are errors.
It is unexpected to not have any events in soar's alerts for those sentinel incidents, it should at least have 1 event with most general info.
We have not seen such issues in our test lab, so we need either detailed connector logs or gcp ticket to investigate.
Im checking if we can add some additional information about this configuration in the docs.
Also please check if you are running latest official integration and connector versions.
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.