Curated dashboard queries: SOAR cases
This document is for Security Operations Center (SOC) managers and analysts who want to monitor threat landscapes and system health using curated dashboards— predefined dashboards designed for visibility across various security use cases. This document provides a collection of curated dashboards and their underlying queries for the SOAR casessource type.
You can use these queries in the query editor or as a baseline for custom widgets. For information on how to create and manage dashboards, see Manage dashboards .
| Dashboard name | Description | Chart name | Query |
|---|---|---|---|
|
CIS Controls Compliance Overview
|
Provides a central view of CIS compliance metrics, such as asset accuracy and backup reliability. use these insights to strengthen security governance and track remediation progress. | Case Distribution by Priority - Open Cases |
|
|
Case & Incident Analytics (SOAR)
|
Provides a centralized view of case management and incident response, enabling teams to resolve threats faster and continuously improve operational efficiency. | Top 10 MITRE Tactics by Incident |
|
|
Case & Incident Analytics (SOAR)
|
Provides a centralized view of case management and incident response, enabling teams to resolve threats faster and continuously improve operational efficiency. | Top 10 Incidents by Case Stage |
|
|
Case & Incident Analytics (SOAR)
|
Provides a centralized view of case management and incident response, enabling teams to resolve threats faster and continuously improve operational efficiency. | Case Tags Distribution |
|
|
Case & Incident Analytics (SOAR)
|
Provides a centralized view of case management and incident response, enabling teams to resolve threats faster and continuously improve operational efficiency. | Total Environments |
|
|
Case & Incident Analytics (SOAR)
|
Provides a centralized view of case management and incident response, enabling teams to resolve threats faster and continuously improve operational efficiency. | Total Important Cases |
|
|
Case & Incident Analytics (SOAR)
|
Provides a centralized view of case management and incident response, enabling teams to resolve threats faster and continuously improve operational efficiency. | Incident Statuses Distribution |
|
|
Case & Incident Analytics (SOAR)
|
Provides a centralized view of case management and incident response, enabling teams to resolve threats faster and continuously improve operational efficiency. | Case Statuses Distribution |
|
|
Case & Incident Analytics (SOAR)
|
Provides a centralized view of case management and incident response, enabling teams to resolve threats faster and continuously improve operational efficiency. | High Priority Cases |
|
|
Case & Incident Analytics (SOAR)
|
Provides a centralized view of case management and incident response, enabling teams to resolve threats faster and continuously improve operational efficiency. | Top 10 Incidents by Case Tag |
|
|
Case & Incident Analytics (SOAR)
|
Provides a centralized view of case management and incident response, enabling teams to resolve threats faster and continuously improve operational efficiency. | Case Distribution by Priority - Closed Cases |
|
|
Case & Incident Analytics (SOAR)
|
Provides a centralized view of case management and incident response, enabling teams to resolve threats faster and continuously improve operational efficiency. | Recent Incident Details |
|
|
Case & Incident Analytics (SOAR)
|
Provides a centralized view of case management and incident response, enabling teams to resolve threats faster and continuously improve operational efficiency. | Cases Over Time |
|
|
Case & Incident Analytics (SOAR)
|
Provides a centralized view of case management and incident response, enabling teams to resolve threats faster and continuously improve operational efficiency. | Case Statistics |
|
|
Case & Incident Analytics (SOAR)
|
Provides a centralized view of case management and incident response, enabling teams to resolve threats faster and continuously improve operational efficiency. | Incident Closure Reasons Distribution |
|
|
Case & Incident Analytics (SOAR)
|
Provides a centralized view of case management and incident response, enabling teams to resolve threats faster and continuously improve operational efficiency. | Incident Severities Distribution |
|
|
Case & Incident Analytics (SOAR)
|
Provides a centralized view of case management and incident response, enabling teams to resolve threats faster and continuously improve operational efficiency. | Incidents Over Time |
|
|
Case & Incident Analytics (SOAR)
|
Provides a centralized view of case management and incident response, enabling teams to resolve threats faster and continuously improve operational efficiency. | Incident Priorities Distribution |
|
|
Case & Incident Analytics (SOAR)
|
Provides a centralized view of case management and incident response, enabling teams to resolve threats faster and continuously improve operational efficiency. | Top 10 MITRE Techniques by Incident |
|
|
Case & Incident Analytics (SOAR)
|
Provides a centralized view of case management and incident response, enabling teams to resolve threats faster and continuously improve operational efficiency. | Top 10 Case Tags |
|
|
Case & Incident Analytics (SOAR)
|
Provides a centralized view of case management and incident response, enabling teams to resolve threats faster and continuously improve operational efficiency. | List of Environments |
|
|
Case & Incident Analytics (SOAR)
|
Provides a centralized view of case management and incident response, enabling teams to resolve threats faster and continuously improve operational efficiency. | Top 10 Incidents by Root Cause |
|
|
Case & Incident Analytics (SOAR)
|
Provides a centralized view of case management and incident response, enabling teams to resolve threats faster and continuously improve operational efficiency. | Top 10 Cases Closed |
|
|
Case & Incident Analytics (SOAR)
|
Provides a centralized view of case management and incident response, enabling teams to resolve threats faster and continuously improve operational efficiency. | Low Priority Cases |
|
|
Case & Incident Analytics (SOAR)
|
Provides a centralized view of case management and incident response, enabling teams to resolve threats faster and continuously improve operational efficiency. | Case Actions Over Time |
|
|
Case & Incident Analytics (SOAR)
|
Provides a centralized view of case management and incident response, enabling teams to resolve threats faster and continuously improve operational efficiency. | Case Distribution by Priority - Open Cases |
|
|
Case & Incident Analytics (SOAR)
|
Provides a centralized view of case management and incident response, enabling teams to resolve threats faster and continuously improve operational efficiency. | Total Open Incidents |
|
|
Case & Incident Analytics (SOAR)
|
Provides a centralized view of case management and incident response, enabling teams to resolve threats faster and continuously improve operational efficiency. | Case Priorities Distribution |
|
|
Case & Incident Analytics (SOAR)
|
Provides a centralized view of case management and incident response, enabling teams to resolve threats faster and continuously improve operational efficiency. | Total Closed Incidents |
|
|
Case & Incident Analytics (SOAR)
|
Provides a centralized view of case management and incident response, enabling teams to resolve threats faster and continuously improve operational efficiency. | Case Closure Reason Distribution |
|
|
FEDRAMP Continuous Monitoring
|
Provides visibility into Fedramp compliance metrics and vulnerability tracking. Use these insights to prioritize remediation efforts and ensure a strong security posture. | Case Distribution by Priority - Closed Cases |
|
|
FEDRAMP Continuous Monitoring
|
Provides visibility into Fedramp compliance metrics and vulnerability tracking. Use these insights to prioritize remediation efforts and ensure a strong security posture. | Case Distribution by Priority - Open Cases |
|
|
HIPAA Dashboard
|
Provides visibility into PHI access and potential HIPAA violations to support proactive risk management. ensure the ePHI_assets.Hostname
data table is created for charts to load. |
Open Cases Distribution by Priority |
|
|
ISO27001 - Organizational Controls
|
Provides real-time tracking of ISO 27001 audit metrics and security controls to identify gaps and maintain compliance. Note: Filters are required to refine results. | Top 10 Analysts by Incident Closures |
|
|
ISO27001 - Organizational Controls
|
Provides real-time tracking of ISO 27001 audit metrics and security controls to identify gaps and maintain compliance. Note: Filters are required to refine results. | Average Case Closure Time by Priority |
|
|
SOC Workflow Monitoring (SOAR)
|
Provides centralized tracking of alert detection, incident handling, and case management metrics. Use these insights to optimize resources, improve response efficiency, and maintain adherence to SLAs. | Case Closure Time |
|
|
SOC Workflow Monitoring (SOAR)
|
Provides centralized tracking of alert detection, incident handling, and case management metrics. Use these insights to optimize resources, improve response efficiency, and maintain adherence to SLAs. | Total Incidents Handled Automatically |
|
|
SOC Workflow Monitoring (SOAR)
|
Provides centralized tracking of alert detection, incident handling, and case management metrics. Use these insights to optimize resources, improve response efficiency, and maintain adherence to SLAs. | Analyst's Performance |
|
|
SOC Workflow Monitoring (SOAR)
|
Provides centralized tracking of alert detection, incident handling, and case management metrics. Use these insights to optimize resources, improve response efficiency, and maintain adherence to SLAs. | Automatically vs Manually Handled Incidents Over Time |
|
|
SOC Workflow Monitoring (SOAR)
|
Provides centralized tracking of alert detection, incident handling, and case management metrics. Use these insights to optimize resources, improve response efficiency, and maintain adherence to SLAs. | Case Closure Summary |
|
|
SOC Workflow Monitoring (SOAR)
|
Provides centralized tracking of alert detection, incident handling, and case management metrics. Use these insights to optimize resources, improve response efficiency, and maintain adherence to SLAs. | Total Incidents Handled Manually |
|
|
SOC Workflow Monitoring (SOAR)
|
Provides centralized tracking of alert detection, incident handling, and case management metrics. Use these insights to optimize resources, improve response efficiency, and maintain adherence to SLAs. | Top 10 Analysts by Incident Closure |
|
|
SOC Workflow Monitoring (SOAR)
|
Provides centralized tracking of alert detection, incident handling, and case management metrics. Use these insights to optimize resources, improve response efficiency, and maintain adherence to SLAs. | Top 10 Users by Case |
|
|
SOC Workflow Monitoring (SOAR)
|
Provides centralized tracking of alert detection, incident handling, and case management metrics. Use these insights to optimize resources, improve response efficiency, and maintain adherence to SLAs. | Average Case Closure Time by Priority |
|
|
SOC Workflow Monitoring (SOAR)
|
Provides centralized tracking of alert detection, incident handling, and case management metrics. Use these insights to optimize resources, improve response efficiency, and maintain adherence to SLAs. | Case Assignments Over Time |
|
|
SOC Workflow Monitoring (SOAR)
|
Provides centralized tracking of alert detection, incident handling, and case management metrics. Use these insights to optimize resources, improve response efficiency, and maintain adherence to SLAs. | Alert Detection Summary |
|
|
Security Management Overview
|
Provides centralized visibility into response performance and operational trends. It helps security teams track progress and make informed decisions to strengthen the security posture. | Open Cases by Age |
|
|
Security Management Overview
|
Provides centralized visibility into response performance and operational trends. It helps security teams track progress and make informed decisions to strengthen the security posture. | Cases Last Update more than 7 Days Ago |
|
|
Security Management Overview
|
Provides centralized visibility into response performance and operational trends. It helps security teams track progress and make informed decisions to strengthen the security posture. | Open Case Tags Overview - 7 days |
|
|
Security Management Overview
|
Provides centralized visibility into response performance and operational trends. It helps security teams track progress and make informed decisions to strengthen the security posture. | Analyst Productivity (Closed Cases) - 7 days |
|
|
Security Management Overview
|
Provides centralized visibility into response performance and operational trends. It helps security teams track progress and make informed decisions to strengthen the security posture. | Open Cases by Environment - Last 7 Days |
|
|
Security Management Overview
|
Provides centralized visibility into response performance and operational trends. It helps security teams track progress and make informed decisions to strengthen the security posture. |
|
|
|
Security Management Overview
|
Provides centralized visibility into response performance and operational trends. It helps security teams track progress and make informed decisions to strengthen the security posture. | Analyst Workloads |
|
|
Security Management Overview
|
Provides centralized visibility into response performance and operational trends. It helps security teams track progress and make informed decisions to strengthen the security posture. |
|
|
|
Security Management Overview
|
Provides centralized visibility into response performance and operational trends. It helps security teams track progress and make informed decisions to strengthen the security posture. | % Automated Closure - Last 7 Days |
|
|
Security Management Overview
|
Provides centralized visibility into response performance and operational trends. It helps security teams track progress and make informed decisions to strengthen the security posture. | Cases Priority - Last 24 Hours |
|
|
Security Management Overview
|
Provides centralized visibility into response performance and operational trends. It helps security teams track progress and make informed decisions to strengthen the security posture. | MTTR by SOC Role - Last 7 Days |
|
|
Security Management Overview
|
Provides centralized visibility into response performance and operational trends. It helps security teams track progress and make informed decisions to strengthen the security posture. | Open Critical/High Cases - Last 24 Hours |
|
|
Security Management Overview
|
Provides centralized visibility into response performance and operational trends. It helps security teams track progress and make informed decisions to strengthen the security posture. | Analyst Backlog (Open Cases) - 7 days |
|
|
Security Management Overview
|
Provides centralized visibility into response performance and operational trends. It helps security teams track progress and make informed decisions to strengthen the security posture. |
|
|
|
Security Management Overview
|
Provides centralized visibility into response performance and operational trends. It helps security teams track progress and make informed decisions to strengthen the security posture. | Top 10 MITRE ATT&CK Tactics - Last 7 Days |
|
|
Security Management Overview
|
Provides centralized visibility into response performance and operational trends. It helps security teams track progress and make informed decisions to strengthen the security posture. |
|
|
|
Security Management Overview
|
Provides centralized visibility into response performance and operational trends. It helps security teams track progress and make informed decisions to strengthen the security posture. | Top 10 MITRE ATT&CK Techniques - Last 7 Days |
|
Need more help? Get answers from Community members and Google SecOps professionals.

