Dynamically populate description of an incident

Brass Contributor


Is it possible to populate the description of an incident dynamically? For example, I have an analytic rule which detects if an account is added to a specific group. I would like to populate the incident description as below:

"user XYZ has added user ABC to the domain group GRP01". 

Here, the XYZ, ABC, and GRP01 is extracted from the query result (SubjectUserName, MemberName, TargetUserName. This would make the incidents more easy to understand by analysts at first glance, without having to investigate evidence events. Also, when integrating with a ticketing system, the dynamically populated description would be more useful for incident handlers. 

2 Replies
best response confirmed by mergene (Brass Contributor)

@mergene This is not currently possible, however we are working on such a feature.

Thanks Ofer! Looking forward to it!