GoogleSecOpsCases
Use the Google SecOps Cases integration to retrieve Cases as Incidents. This integration also provides commands to manage the Cases lifecycle.
- Category
- Analytics & SIEM
- Pack
- GoogleChronicleBackstory
Configuration parameters
- credentials — (required)
- url_format — API URL Format
- secops_project_instance_id — Google SecOps Project Instance ID (required)
- secops_project_number — Google SecOps Project Number
- region — Region (required)
- other_region — Other Region
- isFetch — Fetch incidents
- incidentType — Incident type
- first_fetch — First Fetch Time
- max_fetch — How many incidents to fetch each time
- case_priorities — Case Priorities
- case_statuses — Case Statuses
- case_environments — Case Environments
- case_tags — Case Tags
- case_filter_logic — Case Filter Logic
- incidentFetchInterval — Incidents Fetch Interval
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
Commands (36)
- gcb-case-alert-customfield-list — Retrieve the list of custom field values associated with a case alert.
- gcb-case-alert-entity-create — Manually create a new involved entity within a case alert.
- gcb-case-alert-entity-get — Retrieve detailed information about a specific involved entity in a case alert.
- gcb-case-alert-entity-list — Retrieve the list of entities associated with a case alert.
- gcb-case-alert-entity-property-add — Add a new custom property to an involved entity in a case alert.
- gcb-case-alert-entity-property-update — Update an existing custom property value on an involved entity in a case alert.
- gcb-case-alert-entity-update — Update the attributes of an existing involved entity in a case alert.
- gcb-case-alert-get — Retrieve detailed information about a specific case alert by its ID.
- gcb-case-alert-list — Retrieve the list of alerts associated with the specified case.
- gcb-case-alert-move — Move a case alert to a different case. Note: Both source and destination cases must be open.
- gcb-case-alert-recommendation-create — Initiate an asynchronous AI recommendation for a case alert.
- gcb-case-alert-recommendation-fetch — Fetch a previously generated AI recommendation for a case alert.
- gcb-case-alert-sla-pause — Pause the SLA timer for the specified case alert.
- gcb-case-alert-sla-resume — Resume the SLA timer for the specified case alert.
- gcb-case-alert-sla-set — Set the SLA parameters for a case alert. Note: When critical_time is specified, total_time must be greater than critical_time.
- gcb-case-alert-tag-add — Add a tag to a case alert.
- gcb-case-alert-tag-remove — Remove a tag from a case alert.
- gcb-case-alert-update — Update the properties of an existing case alert.
- gcb-case-assign — Assign the specified cases to a specific analyst or SOC role.
- gcb-case-close — Close the specified cases.
- gcb-case-close-definition-list — Retrieve the list of case close definitions configured in the instance.
- gcb-case-comment-create — Add a comment to the specified case.
- gcb-case-comment-list — Retrieve the list of comments associated with the specified case.
- gcb-case-get — Retrieve a specific case by its ID.
- gcb-case-list — Retrieve the list of cases.
- gcb-case-priority-change — Change the priority of the specified cases.
- gcb-case-reopen — Reopen the specified cases.
- gcb-case-sla-pause — Pause the SLA timer for the specified case.
- gcb-case-sla-resume — Resume the SLA timer for the specified case.
- gcb-case-stage-change — Change the workflow stage of the specified cases.
- gcb-case-stage-definition-list — Retrieve the list of case stage definitions configured in the instance.
- gcb-case-tag-add — Add the specified tags to the cases.
- gcb-case-tag-remove — Remove the specified tag from a case.
- gcb-case-update — Update the properties of a case.
- gcb-playbook-attach — Manually attach (trigger) a specific playbook to a case alert.
- gcb-playbook-list — Retrieve the list of all playbooks that are currently enabled and ready for execution.