Skip to main content
Question

Highlighted Fields not visible in Entities Highlights widget

  • July 20, 2026
  • 2 replies
  • 14 views

AnimSparrow
Forum|alt.badge.img+6

First of all this issue appear around 1month ago? Before I am sure that we were able to see highlights.


I am having an issue with Highlighted Fields properties not rendering below entity inside the Entities Highlights widget at the bottom of the Alert View/Case View.

Specifically, Google SecOps automatically maps our network ranges and populates the Network Name property for IP addresses (ADDRESS entity type). But same is for custom ones created by us that worked previously.

Although the data is successfully populated and visible in other parts of the UI, it refuses to appear directly on the entity rows/cards in the main alert view.

What I have already checked and verified:

  • Properties Metadata: The Network Name field has both Is displayed and Is highlighted checkboxes checked.

  • Side Panel & Entity Details: The configuration works perfectly for the right-hand side panel (Highlighted Fields section) and inside the SOAR Search -> Entity Details view. The field is there, and the value (e.g., FNC | INS servers) is correctly visible.

  • Group Name Testing: I tested changing the Group name in Metadata settings between Entity and ADDRESS (matching the entity type), but it made no difference – the cards still don’t show the value.

  • New Cases: All configuration changes were tested on newly generated cases to rule out caching/historical data issues, but the field remains missing on the summary cards.

It seems like the bottom Entities Highlights widget is ignoring the global metadata layout settings for these cards.

Has anyone faced this issue? Is there a specific way to force the card layout to inherit this custom property, or is this widget hard-coded to only show default system fields (like Description)?

 

 

2 replies

whathehack81
Forum|alt.badge.img+5

Your configuration appears correct, and this does not look like the widget being intentionally limited to default fields.

The current Google SecOps documentation states that fields marked Is highlighted in Properties Metadata should appear in the Entities Highlights widget when the field is part of the entity.

Since Network Name is populated and appears under Entity Details → Highlighted Fields, the entity mapping and metadata are being applied successfully. The failure appears isolated to the summary-card renderer.

I would perform one final isolation test:

Open the same entity through Explore.

Select Network Name and use Add to highlight.

Test it in both the default alert view and any playbook/role-specific alert view.

If it remains absent in both views, I would treat this as a product regression and open a support case with the case ID, alert ID, entity type, property system name, active alert-view name, and approximate date the behavior changed.

There does not appear to be another supported setting for forcing the property onto the entity card.

The default and playbook-specific views are worth distinguishing because the active Alert Overview layout can come from either the administrator-defined default or a role-specific playbook view. 🧠


AnimSparrow
Forum|alt.badge.img+6
  • Author
  • Bronze 5
  • July 21, 2026

Your configuration appears correct, and this does not look like the widget being intentionally limited to default fields.

The current Google SecOps documentation states that fields marked Is highlighted in Properties Metadata should appear in the Entities Highlights widget when the field is part of the entity.

Since Network Name is populated and appears under Entity Details → Highlighted Fields, the entity mapping and metadata are being applied successfully. The failure appears isolated to the summary-card renderer.

I would perform one final isolation test:

Open the same entity through Explore.

Select Network Name and use Add to highlight.

Test it in both the default alert view and any playbook/role-specific alert view.

If it remains absent in both views, I would treat this as a product regression and open a support case with the case ID, alert ID, entity type, property system name, active alert-view name, and approximate date the behavior changed.

There does not appear to be another supported setting for forcing the property onto the entity card.

The default and playbook-specific views are worth distinguishing because the active Alert Overview layout can come from either the administrator-defined default or a role-specific playbook view. 🧠

no results. I will go with the ticket