When a detection signal is configured to use a ServiceNow connector, it should give user an option to create multiple cases. One case per alert. For example, user should have an option to chose whether she/he wants to bundle all of the alerts into one single SNOW case like in the screenshot but also should have an option to tell Elastic to create separate caes per host
Describe a specific use case for the feature:
There are going to be use cases where users need to have separate cases per alert/host in ServiceNow for separate investigation or automated remediation. This feature will enable users to do so
Describe the feature:
When a detection signal is configured to use a ServiceNow connector, it should give user an option to create multiple cases. One case per alert. For example, user should have an option to chose whether she/he wants to bundle all of the alerts into one single SNOW case like in the screenshot but also should have an option to tell Elastic to create separate caes per host
Describe a specific use case for the feature:
There are going to be use cases where users need to have separate cases per alert/host in ServiceNow for separate investigation or automated remediation. This feature will enable users to do so