Conversation
… SOAR MCP tool suite Consolidates and rolls up the full Chronicle 1P Case, CaseAlert, and SOAR MCP tool suite across secops-mcp and secops-soar-mcp: - Rolls up PR #282 (soar_trigger): Chronicle 1P CaseService & CaseAlertService core tools, SOAR reaction triggers, Entity Investigation, Integration & Action execution, Playbook management, and Connector Event management - Rolls up PR #318 (add-case-creation-mcp-tools): create_case (legacyCases:createCase), create_manual_case (legacyCases:createManualCase), create_or_update_case (legacy:legacyCreateOrUpdateCase), batch_get_legacy_cases (legacy:legacyBatchGetCases) - Rolls up PR #314 (Issue #124): Case close root cause discovery (list_case_close_definitions, get_case_close_definition, create_case_close_definition, update_case_close_definition, delete_case_close_definition, list_case_close_root_causes) - Rolls up PR #234 & PR #281 (soar-case-management-tools): SOAR case lifecycle, priority, bulk actions, and root cause enumeration - Adds full v1main Case sub-resource parity: CaseStageDefinitionService, CaseTagDefinitionService, CaseWallService (comments, wall records, external links, pinned items, chat records, insights), CaseDetectionsService, CaseEventService, CaseInvestigationService, CaseHistoryService, CaseQueueFilterService, CasesDynamicViewService, CaseAgenticReportService, CaseChatService, and LegacyCaseService simulation/action RPCs
…ha/v1 REST routes with Chronicle v1main protos
- Remove duplicate @server.tool() registrations for execute_manual_action and get_action_result_by_id in case_management.py that were shadowed by integration_management.py
- Update execute_manual_action and get_action_result_by_id in integration_management.py to use v1alpha legacyCases endpoints (legacyCases:executeManualAction and legacyCases:getActionResultById?resultIdStr=...)
- Switch add_alert_tag and remove_alert_tag in case_alert_management.py to v1alpha per case_alert.proto method_versioning restrictions
- Align list_connector_events and get_connector_event with connector_event.proto (/v1alpha/{instance}/cases/{case_id}/caseAlerts/{alert_id}/connectorEvents)
- Align get_involved_entity, list_involved_entities, get_entities_by_alert_group_identifiers, and get_entity_details with involved_entity.proto (v1alpha) and unique_entity.proto (/v1/{instance}/uniqueEntities:fetchFull)
- Align get_playbook, list_playbook_instances, and execute_playbook with legacy_playbook.proto and case.proto
- Add strict URL and query parameter assertions to test_secops_soar_parity.py
… and chat routes with v1main protos
- Fix F821 undefined name in case_alert_management.py list_events_by_alert by delegating to list_case_events (/v1alpha/{parent}/cases/{case}/events)
- Align case_alert_management.py SLA, overview, recommendation, and view routes with case_alert.proto (:setSla, :pauseSla, :resumeSla, :alertOverviewData, GET :resolveOverviewWidget, caseAlerts:fetchRecommendation, :createRecommendationLongRunning, :listAlertViews)
- Align case_detections_and_events.py routes with case_detection.proto (/detections, /detections/{id}/events), case_event.proto (/events), and case_evidence_data.proto (/caseEvidenceDatas)
- Align case_wall_records.py with case_wall_record.proto (PATCH :favorite, GET :fetchActivitiesCount, GET :queryAvailableCaseWallRecordTags)
- Align case_reporting_and_chat.py with agentic_case_report.proto (:generate, GET :download) and case_chat_message.proto (/chatMessages)
- Clean up unused imports across modified test and tool files
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Overview
This Pull Request consolidates all open and in-progress Case, Alert, and SOAR management workstreams across
secops-mcp(google-secops-mcp) andsecops-soar-mcpinto a single, unified, conflict-free branch (feat/comprehensive-case-suite), while completing full API coverage across the Chroniclev1mainCase and Alert proto services (126 Case/Alert/SOAR tools insecops_mcp, plussecops_soar_mcproot cause discovery).Rolled-Up Pull Requests & Issues
This PR supersedes and unifies the following Pull Requests and Issues:
soar_trigger) (and superseded PR feat(secops): add comprehensive SOAR parity tools for Chronicle 1P (Git Stack 2/2) #290soar_parity) — Chronicle 1P Case, CaseAlert, SOAR Reaction Triggers, Entity, Integration, Playbook & Connector Tools:CaseService(list_cases,get_case,update_case,change_case_priority,change_case_stage,assign_case,set_custom_case_fields,add_case_tag,remove_case_tag,add_case_insight,pause_case_sla,resume_case_sla,close_case,reopen_case,execute_bulk_add_case_tag,execute_bulk_assign_case,execute_bulk_change_case_priority,execute_bulk_change_case_stage,execute_bulk_close_case,execute_bulk_reopen_case)CaseAlertService(list_case_alerts,get_case_alert,update_case_alert,change_alert_priority,set_alert_custom_fields,move_case_alert,add_alert_tag,remove_alert_tag)entity_investigation.py), Integration & Action Execution (integration_management.py), Playbook Management (playbook_management.py), and Connector Event Management (connector_event_management.py)add-case-creation-mcp-tools-8503933169267217566) — Chronicle REST API Case & Alert Creation Endpoints:create_case(POST /v1alpha/{instance}/legacyCases:createCase— ingestsLegacyCaseCasesPackagecontaining full alert metadata,LegacyCaseSecurityEventUDM/CEF event telemetry, and extracted entities)create_manual_case(POST /v1alpha/{instance}/legacyCases:createManualCase— creates a manual SOAR case viaApiCreateManualCaseRequestwith optionalalertName,entities,priority,assignedUser,tags, andplaybooks)create_or_update_case(POST /v1alpha/{instance}/legacy:legacyCreateOrUpdateCase— creates or updates native SIEMLegacyCaserecords with fixedlegacy:legacyCreateOrUpdateCasecustom verb routing)batch_get_legacy_cases(GET /v1alpha/{instance}/legacy:legacyBatchGetCases— batch retrieval of native SIEMLegacyCaseresources)feat/issue-124-case-close-root-causes) & Fixes Need case-close-root-causes in order to close cases #124 — Case Close Root Cause Discovery (secops-mcp&secops-soar-mcp):list_case_close_definitions,get_case_close_definition,create_case_close_definition,update_case_close_definition,delete_case_close_definition(CaseCloseDefinitionServiceinserver/secops/secops_mcp/tools/case_close_definitions.py)list_case_close_root_causesinserver/secops-soar/secops_soar_mcp/case_management.py(GET /api/external/v1/settings/case-close-root-causes)soar-case-management-tools) — SOAR Case Lifecycle & Triage Parity:Full Chronicle
v1mainCase & Alert Service CoverageBeyond the rolled-up PRs, this branch completes coverage across the remaining Chronicle
v1mainCase sub-resource services:CaseService(case.proto):merge_cases(POST /v1/{instance}/cases:mergewithcasesIds(int32[]) andcaseToMergeWith(int32) to combine cases, alerts, and event telemetry into a target case)get_or_create_case_summary,get_case_overview,mark_case_important,mark_case_incident,set_case_sla,attach_playbook_to_case,fetch_case_affected_Playbookslist_case_tasks,get_case_task,create_case_task,update_case_task,delete_case_tasklist_case_involved_relations,list_case_involved_eventsCaseAlertService(case_alert.proto):set_alert_sla,get_alert_overview,fetch_alert_group_events,fetch_alert_grouping_fields,import_alert_from_siem,mark_alert_important,close_case_alert,reopen_case_alertCaseCloseDefinitionService,CaseStageDefinitionService&CaseTagDefinitionService(case_close_definitions.py):list,get,create,update,delete) for Case Close Root Cause Definitions, Case Stage Definitions (caseStageDefinitions), and Case Tag Definitions (caseTagDefinitions)CaseWallService(case_wall_records.py):list_case_comments,get_case_comment,create_case_comment,update_case_comment,delete_case_commentlist_case_wall_records,get_case_wall_recordlist_case_external_links,create_case_external_link,update_case_external_link,delete_case_external_linklist_case_pinned_items,create_case_pinned_item,delete_case_pinned_itemlist_case_chat_records,create_case_chat_recordCaseDetectionsService,CaseEventService&CaseInvestigationService(case_detections_and_events.py):list_case_detections,get_case_detection,query_case_detections_udm_field_valueslist_case_events,get_case_eventget_case_investigation,get_case_investigation_graph,update_case_investigation_graph,list_case_investigation_snapshotsCaseHistoryService,CaseQueueFilterService,CasesDynamicViewService,CaseAgenticReportService&CaseChatService(case_reporting_and_chat.py):list_case_histories,list_case_queue_filters,get_case_queue_filter,create_case_queue_filter,update_case_queue_filter,delete_case_queue_filterget_cases_dynamic_view,update_cases_dynamic_viewlist_case_agentic_reports,get_case_agentic_report,generate_case_agentic_reportsend_case_chat_message,list_case_chat_messagesLegacyCaseService(case_management.py):create_case,create_manual_case,create_or_update_case,batch_get_legacy_casesexecute_manual_action,get_action_result_by_id,simulate_alert,get_custom_cases,is_custom_case_exists,export_custom_case,import_custom_case,delete_use_case,generate_use_cases,inject_sample_data,generate_case_collaborator,add_evidence_to_case,investigator_extend_case_graphVerification
pytest):server/secops/tests/test_case_close_definitions_unit.pyserver/secops/tests/test_case_management_tools.pyserver/secops/tests/test_secops_case_management.pyserver/secops/tests/test_secops_soar_parity.pyserver/secops-soar/tests/unit/test_case_management.pysecopsandsecops-soarpass (32 passed).dandye-0324-chronicle/ltstrtn.backstory.chronicle.security):create_manual_case(legacyCases:createManualCase) creating live SOAR cases (#33288,#33289) with initial alerts (#488839) and entities (ADDRESS,HOSTNAME,USERUNIQNAME).create_case(legacyCases:createCase) ingesting multi-stage alerts (#488840,#488841,#488842) with fullLegacyCaseSecurityEvent(PROCESS_LAUNCH,NETWORK_HTTP) telemetry and entity extraction.merge_cases(cases:merge) andmove_case_alert(cases/{case}/caseAlerts/{alert}:move) attaching ingested alerts and events onto existing cases.create_case_comment,list_case_comments,add_case_tag,list_case_wall_records,list_case_close_definitions,list_case_stage_definitions,list_case_tag_definitions,create_or_update_case(legacy:legacyCreateOrUpdateCase), andbatch_get_legacy_cases(legacy:legacyBatchGetCases).