Skip to main content
Question

SecOps SOAR Chronicle Connector is not ingesting cases created by other instance SOAR connector

  • March 9, 2026
  • 4 replies
  • 62 views

cyberSecGuy
Forum|alt.badge.img+2

Hello.

 

The parent Tenant is pulling cases from a Child Tenant. However, Child’s cases created by SOAR connectors are not pulled by the Parent SOAR connector, only those cases created by rules.

 

Please advise if any configuration changes are required.

 

Thank you. 

4 replies

cmorris
Staff
Forum|alt.badge.img+12
  • Staff
  • March 9, 2026

This is the expected behavior - the Chronicle connector pulls alerts originating in the SIEM. You would need to configure additional connectors for your other sources.


cyberSecGuy
Forum|alt.badge.img+2
  • Author
  • Bronze 1
  • March 9, 2026

What about Federated Cases? https://docs.cloud.google.com/chronicle/docs/soar/admin-tasks/environments/case-federation-secops

Also would this work for multitenant? 


cyberSecGuy
Forum|alt.badge.img+2
  • Author
  • Bronze 1
  • March 10, 2026

Also, by additional connectors, you mean to configure them on the Parent so the cases are pulled directly from the sources instead of the Child?

 

So if it is needed to have all these telemetry in both Parent and Child Tenants, then the same connector needs to be configured on both. 


cmorris
Staff
Forum|alt.badge.img+12
  • Staff
  • March 10, 2026

With the Federated tenant, I believe the sync is from Child (Secondary) to Parent (Primary). That may be an option, if you have a Federated tenant.