Skip to main content

Handling Duplicate Alerts in SOAR with Enabled Connector

  • December 17, 2024
  • 1 reply
  • 14 views

shubham8agar
Forum|alt.badge.img+5

When a custom connector runs automatically and ingests the same alerts, cases, or events (alertInfo/caseInfo objects), does it recreate them or avoid duplication if the same event already exists in the SOAR system under a different case number? While a new test-run is performed it found that it creates a new one but I am curious about the behavior during automatic execution !

1 reply

f3rz
Staff
Forum|alt.badge.img+10
  • Staff
  • December 18, 2024

During ETL (extract, transform, and load), duplicates are skipped, but only if you assign the same Alert Identifier repeatedly.

However, If you generate a new Alert Identifier each time, it won't be skipped.