We've reorganized our documentation navigation structure to align directly with your operational workflows. See the release notes and the walkthrough video for more information.
This document explains how administrators can configure case names in Google Security Operations.
As an administrator, you can control how Google SecOps names
cases. On the SOAR Settings > Case Data > Case Name page, there are five
fields. Google SecOps tries to match each case with the name in
the first field. If there's no match, it moves on to the next field until it
finds one.
To add a case name, follow these steps:
Go to Settings > Case Data > Case Name.
Place your cursor inside the square brackets of the field.
Either manually enter fixed text, or click the brackets next to the field to open the Insert Placeholder dialog.
In the Insert Placeholder dialog, select a placeholder from the Alert,
Case, Event, or Dynamic Environment Parameters menu.
Once selected, the placeholder is automatically inserted into the field.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2026-07-17 UTC."],[],[]]