Hi Pierre,
Thank you for the response.
Kindly assist in the following.
We have around 10 12 different teams working in the organization like Network, Automation, IT Support, System etc.
The customer requires that a escalation rule to exist in which all the different team groups are given a ticket to close. Each ticket's response is based on severity level and then emailed direct to their manager incase of no response.
Scenario 1:
A ticket is created for IT support team with severity 5 consisting of a time period of 5 days for response of closure. IF they do not respond then on the 6th day the ticket is escalated to their manager or higher upper management.
Scenario 2:
A ticket is created to Automation team with severity 1 consisting of a time period of 1 day or few hours for response of closure. IF they do not respond then on the next minute, the ticket is escalated to their manager or higher upper management.
Looking forward to your response.
------------------------------
Usman Saeed Raja
------------------------------
Original Message:
Sent: Mon January 23, 2023 09:36 AM
From: Pierre Dufresne
Subject: IBM Resilient Escalation Rules
Hi,
You could create a task in your incident and mark it with a "due date". Then go to "Administration Settings" and Notifications. There you can create a new notification on the object type "Task" and give it a condition "Due date" is "Past by" the number of days you need. This will send a notification or an email to whom you need.
You could also install the "Timer function for SOAR" and create a workflow or playbook calling the function followed by whatever task needs to be done when the delay parameter in the function is expired.
HTH
------------------------------
Pierre Dufresne
Original Message:
Sent: Mon January 23, 2023 07:07 AM
From: Usman Saeed Raja
Subject: IBM Resilient Escalation Rules
I have a question. I currently have deployed IBM Resilient SOAR version 43 installed in a production environment. As you know that the offense tickets are sent to the designated team to resolve. The question at hand is, that is there any mechanism in Resilient that if the concerned team does not close the ticket directed at them for example since 10 days then we escalate the offense ticket through email to their respective manager or group head?
------------------------------
Usman Saeed Raja
------------------------------