elastic / kibana

Your window into the Elastic Stack
https://www.elastic.co/products/kibana
Other
19.82k stars 8.2k forks source link

[SIEM][Detection Engine][Alerts] Allow Security Detection to generate multiple cases with ServiceNow integration #97662

Open hungnguyen-elastic opened 3 years ago

hungnguyen-elastic commented 3 years ago

Describe the feature:

When a detection signal is configured to use a ServiceNow connector, it should give user an option to create multiple cases. One case per alert. For example, user should have an option to chose whether she/he wants to bundle all of the alerts into one single SNOW case like in the screenshot but also should have an option to tell Elastic to create separate caes per host

image

Describe a specific use case for the feature:

There are going to be use cases where users need to have separate cases per alert/host in ServiceNow for separate investigation or automated remediation. This feature will enable users to do so

elasticmachine commented 3 years ago

Pinging @elastic/security-solution (Team: SecuritySolution)

elasticmachine commented 3 years ago

Pinging @elastic/siem (Team:SIEM)