I am working on a custom dashboard in Google Security Operations (Chronicle) and need guidance on building a source system–wise backlog case count view. The requirement is to create a weekly trend graph that shows the number of open cases, grouped by the originating source system / detection source.
I am looking for clarification on the recommended UDM fields to identify the case source and the best approach to query only open cases and aggregate them on a weekly basis. Any sample queries or best practices for this use case would be appreciated.

