Hi All
Can someone tell me what the Last modified time in the Detection > Alerts menu in Google SecOps means?
What changes from the first detected Detection Time of a detected event cause the Last modified value to be displayed?
Can someone explain what each field means?
Hi @dooyoung,
I couldnยดt find any official documentation besides this one, which isnยดt explaining everything: https://cloud.google.com/chronicle/docs/detection/timestamp-definitions
But from my understanding it is as follows (if thereยดs anyone who can refute this, please correct me)
Detection Time:
Created:
Last Modified:
Hi Maxjunker
According to your explanation, the Alert STATE found as NEW by the detection rule has been changed to OPEN, so Last modified is changed and a Case is automatically created. For some logs, cases are automatically created and for some logs, cases are not created automatically. I don't know the difference.