Skip to main content

Is there a way to implement in SecOps SOAR either via Playbook or something that will automatically notify if the SLA Clock is on critical period?

Hi @JMon38 


The "Set Case SLA Action" can be used within a Playbook to define SLA parameters, including the SLA Period and SLA Time to Critical Period. 


This action sets the breach and critical times relative to the case creation time or the start of a specific case stage. So your playbook needs to account for this when calculating the remaining time and triggering the notification. 


Hi @JMon38  

Did you create the playbook for SLA notification , was it possible?


Hi @ErikaB Could you please help me icouldnt find right parameters to create playbook for that.

I want to define SLA periods in our environment and ensure that our analysts are notified accordingly. For example, if an SLA is defined for 12 hours, the assigned analyst should receive:

  • A medium-priority notification after 6 hours,

  • A critical notification after 8 hours,

  • And a final notification when the SLA is breached (i.e., after 12 hours).


Reply