IBM QRadar SOAR

IBM QRadar SOAR

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Special incident field

    Posted Tue January 02, 2024 01:44 PM

    Hi

    We need to create a field that will be similar to the Owner field and store the same  values.
    This will allow us to define two non-dependent roles for two different users in each incident. Let's say Owner and Incident Manager.

    Field Owner is visible as a regular variable in Customization Settings -> Layouts -> Fields so I guess it can't be duplicated so easily.

    Is it possible to create a new field that would have similar functionality to Owner or Members?

    Thank you



    ------------------------------
    Dominik Siekierski
    ------------------------------


  • 2.  RE: Special incident field

    Posted Tue January 02, 2024 04:49 PM

    Hi Dominik,

    You can create a custom Select field (similar to Owner) and call it Incident Manager and drag it on to the Details layout page where the Owner is.

    You can assign the Incident Manager manually or set it automatically in a script.  Does this answer your question ?



    ------------------------------
    AnnMarie Norcross
    ------------------------------



  • 3.  RE: Special incident field

    Posted Wed January 03, 2024 03:29 AM

    Thanks for the reply.

    Yes I know that you can create a field in Customization Settings -> Layouts. Unfortunately I don't know how to make a field which will have all the functionalities like Owner

    I need features like:
    - Notification when you are selected in this field
    - Values of this field as a self updating list of people in the institution.
    - The values should include the groups of people created in Administrator Settings -> Groups.
    - Hovering the mouse over the field in the incident view should show the person's email, a list of people in the group.
    - etc.



    ------------------------------
    Dominik Siekierski
    ------------------------------