life of a case

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

life of a case

L2 Linker

Hi all,

 

I am trying to figure out the life of a case and run into a question I can't seem to find the documentation about:

What happens when a case has been set to resolved but a new matching issue pops up? Is a new case created or is the resolved case re-opened?

1 REPLY 1

L5 Sessionator

Hello @JohanBogema ,

 

Greetings for the day.

 

In Cortex XSIAM, the behavior when a new matching issue occurs for a resolved case depends on the specific resolution status and the timing of the new alert.

 

1. Automatic Reopening (Within 6-Hour Window):

If a case is resolved with the status Resolved - Auto Resolve, Cortex XSIAM will automatically reopen the case if a matching issue occurs within a six-hour grace period.

  • Status Change: The case status reverts from Resolved back to New to ensure it is visible to analysts.
  • Window Calculation: This six-hour window is based on the timestamp of the last issue that was grouped into the case, not the time the case was marked as resolved.

2. New Case Creation (After 6-Hour Window):

Once the six-hour grouping window has passed, any new matching issues will trigger the creation of a new case for a separate investigation.

 

3. Manual Resolution Behavior:

If a case is resolved manually (for example, using statuses such as Resolved - True Positive or Resolved - False Positive), the system behavior changes to preserve the integrity of the completed investigation.

  • Grouping Disabled: Manual resolution typically sets the Alerts Grouping Status to Disabled.
  • Effect: New matching alerts generally do not reopen the manually resolved case and may instead generate a new case or remain unassociated, depending on the applicable grouping logic.

If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".

 

Thanks & Regards,
S. Subashkar Sekar

  • 39 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!