Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Assign SIEM Signals to a user #76627

Closed
Tracked by #165878
Bananenbrei opened this issue Sep 3, 2020 · 6 comments
Closed
Tracked by #165878

Assign SIEM Signals to a user #76627

Bananenbrei opened this issue Sep 3, 2020 · 6 comments
Labels
8.11 candidate enhancement New value added to drive a business result Feature:Detection Alerts Security Solution Detection Alerts Feature needs design Team:Detection Engine Security Solution Detection Engine Area Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:SIEM Theme: TBD

Comments

@Bananenbrei
Copy link

Describe the feature:
When a User changes the status of a SIEM Signal from "open" to "in progress" or "closed" there should be information within the signal to show who did this. An option to filter Signals based on assigned users would also be great.

Describe a specific use case for the feature:
Multiple Analysts work on one SIEM and they start marking Signals as "in progress" - this can get messy depending on the amount of signals

An analyst sets a signal marked as "in progress" and then forgot about it. It is now open for 2 weeks+ and you are unable to tell who is at fault here. If such a feature would exist the Analyst could see what Signals are assigned to him.

Forum Thread where I made the same request for reference:
https://discuss.elastic.co/t/feature-request-alert-assignment-to-user/247095

@lukeelmers lukeelmers added enhancement New value added to drive a business result Team:SIEM triage_needed labels Sep 4, 2020
@elasticmachine
Copy link
Contributor

Pinging @elastic/siem (Team:SIEM)

@spong spong added Feature:Detection Rules Anything related to Security Solution's Detection Rules and removed triage_needed labels Sep 4, 2020
@MindyRS MindyRS added the Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. label Oct 27, 2020
@austinsonger
Copy link

Yes if this was a feature it would get closer to a tool where we wouldn't have to create a tickets in another help desk tool.

@chrislujan
Copy link

Agreed, having analysts assigned on rotation would be nice to have.

@the-pixel-hunter
Copy link

please add this

@peluja1012 peluja1012 added Team:Detection Alerts Security Detection Alerts Area Team Feature:Detection Alerts Security Solution Detection Alerts Feature and removed Feature:Detection Rules Anything related to Security Solution's Detection Rules labels Sep 15, 2021
@MindyRS MindyRS added the Team:Detections and Resp Security Detection Response Team label Feb 23, 2022
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-detections-response (Team:Detections and Resp)

@yctercero yctercero added Team:Detection Engine Security Solution Detection Engine Area and removed Team:Detection Alerts Security Detection Alerts Area Team labels May 13, 2023
@yctercero
Copy link
Contributor

This was implemented in 8.12!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
8.11 candidate enhancement New value added to drive a business result Feature:Detection Alerts Security Solution Detection Alerts Feature needs design Team:Detection Engine Security Solution Detection Engine Area Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:SIEM Theme: TBD
Projects
None yet
Development

No branches or pull requests

10 participants