Hi, i was wondering why sometimes in the curated detection rules, for example, severity is medium and Incident criticality level is only informational?
Any ideas?
Thanks!
Solved! Go to Solution.
I did a bit of digging and I believe that the rule you are alerting on has a severity of Info on it which aligns to your dot in the alert tab you pointed toward. The risk score in the rule is set to 35 which also aligns to the risk score you are showing.
It appears that the Google Chronicle Alert connector had an issue that the Fallback Severity in the connector was taking precedence over the severity that was in the rule.
The upcoming version of the alert connector in the marketplace v52 should resolve this issue and should be available next week.
More broadly, we are taking the value in the severity field within the rule and mapping it to the field alert.priority so any playbook integration or viewing of that field can be found there. That value is being mirrored in the Threat section in an investigation which is where the problem is arising.
If you modify the priority in a case, the priority will be the only value impacted, the severity will remain what it was initially.
Hope this clarifies at least a few things.