Skip to main content
Question

Execution Playbooks on Alerts only

  • February 12, 2026
  • 1 reply
  • 0 views

bitshock1015
Forum|alt.badge.img+2

Its possible to run a playbook only in alerts?

Im trying to make a playbook run for specific alerts but, in alert & iocs im not founded the playbook execution for specific alert.


the reason of this is the delay from alert and opening a case on SOAR. im get a big difference between start time from alert to a create a case (2h~)

1 reply

cmorris
Staff
Forum|alt.badge.img+11
  • Staff
  • February 12, 2026

Alerts need to be ingested into the SOAR via the Chronicle connector prior to playbook execution. Can you provide further details on the alerts that are being delayed - rule types, run freq, etc.? Please also check - https://docs.cloud.google.com/chronicle/docs/detection/detection-delays.