For each Elastic SIEM alert, create a GitHub Issue to triage and handle incidents. When used with detection-as-code, pull requests can be opened referencing GitHub Issues for rule tuning.
How it works
Import this story to your tenant, from where you can adapt it to meet your unique needs.
Import