Hi All, I have added few use case name to the dynamic whitelist on the Sentinel connector at the Google SecOps SOAR,but some of these alerts are not getting ingested as a SOAR case even though a security incident is created at Sentinel
Hey
Can you provide some examples, when this happened to you?
Hi
For Ex : I added in production usecases- UC01,UC02... etc to the dynamic list.
In Sentinel UC01 generated an sentinel incident and it did not generate a case on the SOAR.
Apologies for the delay, I have created separate dynamic list per use case name
I will check from my end, if I can make it work and let you know
I also see that there is some miss aligned behaviour with the dynamic list. Putting it in the backlog for the team. Current ETA would be to resolve it by the end of Q3.
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.