Skip to main content
Question

How to configure Detection Outcomes Fields for Curated Rules in Google SecOps?

  • March 20, 2026
  • 1 reply
  • 56 views

soaruser
Forum|alt.badge.img+3

I’m working with curated rules and its triggered alerts in Google SecOps SIEM and trying to better understand how to configure Detection Outcome Fields effectively. As we can’t edit curated rules and if the detection outcome field from the curated rule triggered alert doesn’t match with the ontology mapping we have done, then entity section from SOAR case remains blank. Leading to no alert grouping, no meaningful context, playbooks gets failed as entities are blank


Are there any recommended guidelines or examples for configuring Detection Outcome Fields in curated rules?

1 reply

Asura
Forum|alt.badge.img+3
  • March 22, 2026

Hello ​@soaruser,

 

Sadly it is not possible to edit curated detection. This mean no change possible on the outcome side.

It is also giving us trouble specially for risk score, which is not matching our internal scoring.

 

The best option might be to raise a Feature Request on Google.