Detailed Explanation of Subflow 2.3 - Link Alert to Existing Case
9.0
, you should refer to this pageFile Hash: SHA256: abc123...
or an IP address, the subflow will search for cases with the same observables.
Once the relevant case is identified, Subflow 2.3 - Link Alert to Existing Case links the alert to that case. This helps to maintain organized case management by consolidating related alerts into one case, preventing redundancy. Additionally, if the alert’s severity is higher than the linked case’s severity, the subflow updates the case’s severity to match the alert’s, ensuring the case reflects the highest level of urgency.
File Hash: SHA256: abc123...
and severity High
is processed.High
.