Detailed Explanation of Subflow 2 - Create Case
9.0
, you should refer to this page192.168.1.100
and a file hash abc123
, and these match observables in an open case, the alert is linked to that case automatically.
device.external_ip
(e.g., 203.0.113.42
) and sha256
(e.g., xyz789
) will initiate a fresh case if no prior match exists in the system.