Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[SIEM] Case workflow integration with third-party system(s) #50103

Open
8 of 9 tasks
MikePaquette opened this issue Nov 8, 2019 · 5 comments
Open
8 of 9 tasks

[SIEM] Case workflow integration with third-party system(s) #50103

MikePaquette opened this issue Nov 8, 2019 · 5 comments
Labels
Meta Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:SIEM

Comments

@MikePaquette
Copy link

MikePaquette commented Nov 8, 2019

Describe the feature:

Add a basic case workflow integration with third party systems in SIEM app.

Describe a specific use case for the feature:
SOC analysts and investigators using SIEM app need a way to coordinate their work inside SIEM with work being done by them or others in an external case/ticket management system, security incident response system, or security orchestration/automated response system.

Specifically they want to be able to:

  • Open, edit, and close cases within SIEM
  • Cause a corresponding case to be created in an external system
  • Receive notification in the SIEM if the case has been closed in the external system
  • View stats about cases
@elasticmachine
Copy link
Contributor

Pinging @elastic/siem (Team:SIEM)

@peterschretlen
Copy link
Contributor

@MikePaquette there's a lot of interesting overlap between case workflow and some of the emerging concepts in Kibana like actions & connectors, "kibana alerting", user-events, and "kibana notifications" - and I think much of the use case is portable to other domains.

I'd like to see Kibana stack services being able to support aspects of this that are not security & SIEM specific, if there are any gaps we should fill them.

cc @alexfrancoeur @bmcconaghy

@pmuellr
Copy link
Member

pmuellr commented Nov 22, 2019

Receive notification in the SIEM if the case has been closed in the external system

Ideally you'd like the external system to make an http request into Kibana to indicate a case has been closed, but ... we're not there yet. Kinda falls into the "chat-ops" or related areas.

In the meantime however, creating an an alert or even just task manager task to somehow look for "newly closed cases" or such could work.!

@stephmilovic
Copy link
Contributor

Related Issues:
[SIEM] [Case] ServiceNow Actions #57866
[SIEM] [Case] Configure Cases Page #57864
[SIEM] [Case] All Cases Page #57865
[SIEM] [Case] To dos #57861
[SIEM] [Case] Editable Case View #57863

@cnasikas
Copy link
Member

cnasikas commented Mar 9, 2020

Related PRs:

[SIEM][CASES] Configure cases: Final #59358
[SIEM][CASE] ServiceNow executor #58894

@MindyRS MindyRS added the Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. label Oct 27, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Meta Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:SIEM
Projects
None yet
Development

No branches or pull requests

7 participants