Attach playbooks to alerts or cases
This document outlines the attachment limits and priority settings for playbooks associated with an alert or case in Google Security Operations, followed by the steps necessary to manually add a playbook or playbook block to an active investigation.
Attachment and execution limits
To preserve platform stability, keep track of the following capacity thresholds:
- Alert scope limits: You can attach a total of 10 playbooks to any single alert. Only one playbook can attach automatically using an ingestion trigger, and an additional 9 playbooks can be attached manually. (Customers who have the Reaction Triggers feature or the Cases playbook feature enabled can attach a total of 30 playbooks.)
- Case scope limits: The platform supports attaching up to 30 playbooks directly to a case container. Similar to alert playbooks, the system limits automatic playbook attachment upon ingestion to one case playbook per case. (This feature is not available to all customers in all regions.)
- Rerun limits: Each unique playbook can be rerun a maximum of 10 times within a single case or alert. (Customers who have the Reaction Triggers feature or the Cases playbook feature enabled can rerun playbooks up to 30 times.)
Playbook execution priority
You can set a playbook's priority between 1 (highest priority) and 3 (lowest priority). If multiple playbooks are attached, the playbook with the highest priority executes first. The default priority is 2 (medium).
Manually attach a playbook or playbook block
To add an existing playbook or a modular playbook block directly to an alert or case, follow these steps:
- In the Cases or Alert tab, click the specific container where you want to add the playbook.
- On the Playbooks tab, click Add Playbook.
- Choose the playbook or the playbook block to add.
- Set the execution priority (the default is 2).
- If the selected playbook block requires input parameters, confirm or modify the fields inside the Inputs dialog. If no inputs are required by the block logic, this dialog is skipped automatically.
The added playbook or playbook block appears directly on the Playbooks tab in the case or alert overview.
Need more help? Get answers from Community members and Google SecOps professionals.