Hi everyone,
We have installed the SOAR plugin in our QRadar installation and it is working fine.
I have configured an escalation template to associate the QRadar offense field {{ offense.assigned_to }} to the SOAR field "QR Assigned" that was created upon the installation of the "QRadar Enhanced Data Migration" extension in SOAR.
When the value of the QRadar field "Assigned to" is changed, the "QR Assigned" in SOAR is automatically updated but the reverse is not true: a change in SOAR does not update the QRadar field.
Is this an option that needs to be configured in the SOAR plugin?
Is there another way of doing this? Like a SOAR function or an API call?
My use case is this: the offense in QRadar will automatically escalate to SOAR where some script will assign the incident to someone. We would like to update the QRadar offense with the name of the owner of the incident in SOAR.
Note: our QRadar and SOAR installation are in the cloud and both share the same user names.
Thanks for your help
------------------------------
Pierre Dufresne
------------------------------