Skip to main content
Question

Latency between SOAR Case updates and SecOps Dashboards

  • January 19, 2026
  • 3 replies
  • 46 views

ar3diu
Forum|alt.badge.img+9

I have noticed a delay regarding how quickly data about changes on cases in the SOAR UI propagates to the SecOps Dashboards datasets, “case” and ”case_history”.

Currently, it takes almost an hour for the database used by the dashboards to update with the latest changes made to cases in the SOAR UI. (e.g. a case going from OPEN > CLOSED).

Is this the intended/expected behavior?

3 replies

ar3diu
Forum|alt.badge.img+9
  • Author
  • Silver 2
  • January 19, 2026

Another point: shouldn't the SecOps Dashboards timestamp filter apply to the case.update_time instead of the case.create_time?


kentphelps
Staff
Forum|alt.badge.img+11
  • Staff
  • January 21, 2026

Take a look at cmmartin_google’s excellent entry on his That SIEM Guy blog on Medium:


ar3diu
Forum|alt.badge.img+9
  • Author
  • Silver 2
  • January 22, 2026

@kentphelps it’s not the same thing.

I’m talking about SOAR Case metadata changes that are not immediately pushed to the backend used by Dashboards API.