Hi all!
Has anyone created dashboards based on SecOps tags? I have to create some reports every quarter based on certain tags which are set for each case using predetermined categories.
The issues that I am facing are:
If you have any advice on modifying the SOAR dashboards for this use case (More than 10 results and the ability to combine tags to create a category) or using Native dashboards for this use case would be greatly appreciated.
TIA
---
Edit: Attempts to use SOAR Advanced Reports results in a NULL element for Case Tags - this has been submitted to Google support for further investigation:
Solved! Go to Solution.
I believe it's in private preview, with a hope for a wider release in the coming weeks, is there a chance you can wait for those?
Depending on your SOAR deployment you might also have 'Advanced Reports' (Looker based), but it seems high effort low return to start that learning curve at this point in time.
I don't think you will achieve this with the 'original' SOAR dashboards, sorry
Andy
Native dashboards will replace this in the near future, if you can wait for those to come out you will have a much better experience.
Talk to your support team to get more info on the feature and it's timelines.
HTH
Andy
@SoarAndy we have the Native dashboards enabled, do you know what type of a query would be able to extract tag information? I haven't been able to find the tag "variables / information" within the query suggestions.
Native dashboard today are only for SIEM data, though at some point, they will include SOAR data (you would need to talk to your support team to enquire about the possibility of previews)
Hi @SoarAndy, I spoke with our account team and the SOAR component isn't available at this time. Just to confirm, there are no other methods currently available to solve for this use case?
I believe it's in private preview, with a hope for a wider release in the coming weeks, is there a chance you can wait for those?
Depending on your SOAR deployment you might also have 'Advanced Reports' (Looker based), but it seems high effort low return to start that learning curve at this point in time.
I don't think you will achieve this with the 'original' SOAR dashboards, sorry
Andy