Hello! I'm trying to use source_grouping_identifier to drive alert grouping in SOAR. There's a relevant post here, and the SOAR documentation is here.
The field is showing on the SOAR UI, but SOAR is creating a separate case for each alert rather than grouping them into the same case. Has anyone had any success using source_grouping_identifier to drive alert grouping? The config seems pretty simple, so I'm not sure what I'm doing wrong. A screenshot of my grouping config is attached. Thanks much!
