Manage tags in cases
This document explains how to manage tags in Google Security Operations cases.
Tags help classify and organize cases for easier filtering and analysis. They can be assigned automatically based on predefined rules or added manually from the Cases page.While you can remove tags from individual cases, the tags themselves remain available in the system.
You may also want to import tags—for example, when migrating from a staging to a production environment or for backup purposes.
Import tags
To import a tag, follow these steps:
- Go to SOAR Settings > Case Data > Tags.
- Click vertical_align_bottom Download template. The CSV file shows the required tag import structure.
- Enter the tag information.
- Click login Import. The imported tags should appear in the platform.
Add a new tag
To add a new tag, follow these steps:
- Go to SOAR Settings > Case Data > Tags.
- Click add Add Tag.
- In the Tag name field, enter a name for the tag.
- Select a match source from Entities, Product, Rule Generator and Vendor.
- From the menu, choose a qualifier that defines how to match the value:
- contains
- exact
- starts with
- ends with
- Select the specific entity or product source. Enter the appropriate Property and Value, if applicable. Alternatively, select the Product, Rule Generator, or Vendor.
- Select the priority for the tag.
Note: Google SecOps merges priority with other alerts and entities and events so that the priority here is not an absolute. - Optional: Select Can be a case name if required. When selected, the tag is assigned as the title of the case if it meets the conditions.
- Click Save.
Need more help? Get answers from Community members and Google SecOps professionals.