[Spotlight Feature] Investigation and case management experience
[Spotlight Feature] Investigation and case management experience
This feature is in public preview. Google SecOps now includes a revamped Investigation Management experience that supports tracking raw UDM events and detections alongside alerts to accommodate new investigation types (such as retrohunt and threat hunt) and higher investigation volumes in cases. You can navigate your case queue using customizable table views, side-drawer previews, and integrated UDM Search workflows. For more information, see Investigation and case management overview.
This preview is currently supported only for single-SIEM deployments (instances where a single Google SecOps SIEM instance ingests data into SOAR) and does not support federated or MSSP environments.
Additional enhancements include:
• Attach SIEM search results to cases: Manually attach individual UDM events or detections directly from SIEM search results to new or existing cases as core evidence (supporting up to 500 detections and 5,000 UDM events per case). For details, see Attach SIEM search results to cases. • Interactive Events Viewer: Dive directly into technical evidence from an interactive side panel. Inspect parsed UDM records, review original raw logs, pin key evidence to your case, and build detection exclusions in real time. For details, see Use the Events Viewer. • Configure new default views: Before enabling the updated Cases experience, set up your default views under SOAR Settings > Case Data > Views. Make sure to manually copy over advanced widget configurations (such as Safe HTML Rendering or custom conditions) from the Default Alert View and Default Case View to the New Default Alert View and New Default Case View to preserve your preferred setups.