One CloudSOC Sequential Incident Detector stopped working
search cancel

One CloudSOC Sequential Incident Detector stopped working

book

Article ID: 263807

calendar_today

Updated On:

Products

CASB Securlet SAAS CASB Advanced Threat Protection CASB Gateway CASB Security Advanced CASB Security Premium CASB Security Standard CASB Security Standard

Issue/Introduction

31 Mar 2023 Client reported one fairly new CloudSOC Sequential Incident Detector was not triggering incidents. 

Client has multiple other Incident Detectors working fine. Only the newer one created recently in early 2023 had stopped working.

 

Resolution

Checked CASB Test Lab. Similar Sequential Incident Detector, recently created in early Mar 2023, also was not triggering incidents.

Found that by deactivating that one Sequential Incident Detector, adding text in the description field, then reactivating it again - it started generating incidents again as expected.

Client did the same steps in their CloudSOC Prod environment and their Sequential Incident Detector also started generating expected incidents as expected.