IBM Security QRadar SOAR

 View Only
  • 1.  Incident Assignment Notification

    Posted Fri May 24, 2024 09:57 AM

    When an offense is sent from SIEM to SOAR and an incident is created, I want to send an email to the concerned user informing them that the incident has been assigned to them. Is there any way or workaround to achieve this



    ------------------------------
    Ahmad Hassan Tariq
    ------------------------------


  • 2.  RE: Incident Assignment Notification

    Posted Fri May 31, 2024 06:32 AM

    Hi Ahmed 

    Reaching out to the development team 

    Regards

    John



    ------------------------------
    John Quirke
    ------------------------------



  • 3.  RE: Incident Assignment Notification

    Posted Tue June 04, 2024 02:45 AM

    Hi Ahmad,

    You can leverage the built-in notification mechanism to sent emails based on certain condition if your SOAR has smtp setup correctly. 

    Go To "Administrator Settings" -> "Notifications", there are some pre-built notification templates which might fit your need, e.g., "Incident Members Changed".

    You can also create your own notification based on required conditions. See more details on this section. https://www.ibm.com/docs/en/sqsp/51?topic=administrator-notifications. Hope it helps.



    ------------------------------
    Gilbert Liao
    ------------------------------