Attach SIEM search results to cases

Supported in:

Google SecOps connects your threat hunting and search workflows directly to case management. You can attach individual UDM events or detections from your SIEM search results table straight to a case as core evidence.

This integration lets you:

  • Enrich an existing case: Add events or detections related to a case you're investigating.
  • Create a new case: Investigate a threat hunt hypothesis.

For more information, see Investigation and case management overview.

Example use case

Consider a threat hunting scenario where an analyst is investigating a suspicious file hash across the organization:

  1. Threat hunt: The analyst runs a UDM search for the hash to evaluate its potential spread.
  2. Evidence selection: Instead of manually exporting search results, the analyst selects the specific events and detections directly from the results table.
  3. Case creation: The analyst creates a new case, which automatically includes those selected items as core evidence.
  4. Investigation & documentation: The analyst documents their findings with internal comments and continues the investigation.

Prerequisites

To attach SIEM search results to a case, your environment must meet the following requirement:

  • Chronicle API migration: Your environment must be migrated to the Chronicle API framework (Stage 2 migration) to allow SIEM data to communicate with the new Cases experience interface.

For more information, see the SOAR migration FAQ and the Chronicle API migration guide.

Supported data types for case evidence

From the SIEM search results table, you can manually attach specific record types to a case:

  • UDM Events: You can attach individual log entries to a case singly or in bulk. There are no restrictions on how many cases a UDM event can link to.
  • Detections: You can add rules engine findings to a case singly or in bulk. There are no restrictions on how many cases a single detection can link to.
  • Alerts: You cannot manually attach alerts to cases from the search results table. The platform automatically ingests and groups alerts into cases using system playbooks and predefined grouping rules. However, you can reassign or move an existing alert to a different case directly from the alert details view.

Create a new case from search results

When you initialize a new case using search data, the platform creates an investigation container and automatically seeds it with your selected parameters.

  1. From the navigation menu, go to Investigation > SIEM Search.
  2. Run a query to find your target data. For more information about filtering your results, see Overview of procedural filtering.
  3. Locate the event or detection data you want to use as evidence.
  4. Open the action menu:
    • For UDM events (Results tab):
      • Single event: Locate your target row and click more_vert.
      • Multiple events: Mark the checkboxes next to the target rows, and then click more_vert.
    • For detections (Alerts & Detections tab):
      • Single detection: Hold the pointer over the target row and click more_vert.
      • Multiple detections: Mark the checkboxes next to the target rows, and then click more_vert.
  5. Select Create case from evidence.
  6. In the Create Case from evidence dialog, configure the following required fields:
    • Title: Enter a descriptive name for the investigation.
    • Environment: Select the target environment scope.
    • Assign to: Designate the owner analyst.
    • Priority: Specify the severity level.
  7. Click Continue.

Attach search results to an existing case

Use this workflow to add new data and historical UDM context to an active investigation.

  1. From the navigation menu, go to Investigation > SIEM Search.
  2. Run a query to find your target data. For more information about filtering your results, see Overview of procedural filtering.
  3. Locate the event or detection data you want to add.
  4. Open the action menu:
    • For UDM events (Results tab):
      • Single event: Locate your target row and click more_vert.
      • Multiple events: Mark the checkboxes next to the target rows, and then click more_vert.
    • For detections (Alerts & Detections tab):
      • Single detection: Hold the pointer over the target row and click more_vert.
      • Multiple detections: Mark the checkboxes next to the target rows, and then click more_vert.
  5. Select Attach to existing case.
  6. From the case list, search for and select your target case.
  7. Confirm the selection to add the data to the case scope.

Troubleshooting

Use this table to quickly resolve common issues encountered while managing evidence from the search interface:

Issue description Root cause and resolution
The assignment options are grayed out or unclickable for a specific row. You selected an alert row. Manual case assignment is disabled for alerts because the platform automatically groups them. Deselect the alert to restore action choices.
The case list does not display the target investigation case. Ensure that your active session environment matches the environment configured on the target case. Mismatched environment boundaries filter out case visibility.

Need more help? Get answers from Community members and Google SecOps professionals.