Skip to main content
Question

How does Google SecOps assign alert priorities

  • August 20, 2025
  • 1 reply
  • 86 views

Forum|alt.badge.img+1

"In Google SecOps, how is the priority of an alert determined? Would like to understand the exact logic behind the priority calculation."
 

 

1 reply

ylandovskyy
Staff
Forum|alt.badge.img+16
  • Staff
  • August 21, 2025

Hey ​@CyberChamp ,

 

Case priority is determined by the highest priority of the Alert within that Case. Alert priority is extracted from the metadata of the 3rd Alert or it’s embedded as part of the Rule for SIEM detections.