Skip to main content

Will "retrohunt" remove existing alerts / cases that were created from previous detections

  • August 24, 2024
  • 3 replies
  • 13 views

Forum|alt.badge.img+2

Hi,

If I run "retrohunt" for a detection rule, will it delete existing alerts and cases from chronicle SOAR  and generate the fresh detections on evaluating historical events  OR it will create duplication and rednundant alerts and cases ?

 

Thanks !

3 replies

Forum|alt.badge.img+8
  • Silver 2
  • August 29, 2024

Hello,

 

Retrohunt does not create or delete existing alerts and cases.

Retrohunt is used to analyze logs and potential alerts against a detection rule before enabling Live Detection. This allows for a thorough evaluation of the rule's effectiveness and helps ensure accurate alerting without impacting the current alert and case management workflow.

Thanks,
Suraj Kadav


Forum|alt.badge.img+2
  • Author
  • New Member
  • September 3, 2024

Thanks, so just to confirm - if I then re-run retrohunt  - 3 times, that will generate 3 * X alerts (based on number of historic events eligible for detection?)


Forum|alt.badge.img+8
  • Silver 2
  • September 3, 2024

Thanks, so just to confirm - if I then re-run retrohunt  - 3 times, that will generate 3 * X alerts (based on number of historic events eligible for detection?)


Hello Swanand,

No. Retrohunt won't generate any alerts.