Google SecOps Chronicle SOAR, when using a custom connector, you can return a CaseInfo() or AlertInfo() object. If CaseInfo() is returned, it creates a case and may generate an event, which sometimes Chronicle treats as an alert.
Can you clarify the following:
- When does Chronicle create an Alert versus an Event?
- What’s the difference between a Case, Alert, and Event?
