{"id":5418,"date":"2022-03-03T16:13:00","date_gmt":"2022-03-03T16:13:00","guid":{"rendered":"http:\/\/www.sumologic.com\/blog\/want-to-improve-collaboration-and-reduce-incident-response-time-try-cloud-soar-war-room"},"modified":"2025-06-17T07:51:48","modified_gmt":"2025-06-17T15:51:48","slug":"want-to-improve-collaboration-and-reduce-incident-response-time-try-cloud-soar-war-room","status":"publish","type":"blog","link":"https:\/\/www.sumologic.com\/blog\/want-to-improve-collaboration-and-reduce-incident-response-time-try-cloud-soar-war-room","title":{"rendered":"Want to improve collaboration and reduce incident response time? Try Cloud SOAR War Room"},"content":{"rendered":"\n<section class=\"e-stn e-stn-0d652506f82b000a392973813b918ee25d5b4211 e-stn--glossary-inner-content e-stn--table-of-content\"><div class=\"container\">\n<div class=\"wp-block-b3rg-row e-row row\">\n<div class=\"wp-block-b3rg-column e-col e-col-1f7b3997080fc292474d26ff00c905d99d3520fa e-col--content-wrapper  col-sm-12 col-lg-12 col-xl-12\">\n<div class=\"e-div e-div-a1b32f66e1749758df41d5aea14f647cd10e362c e-div--card-btn-link\">\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-fd73f00816cbe707f8286d1e8e173ae4\">In the last twenty years, more technology has been produced since the beginning of human history. And while we have talked about industrial automation since 1952, the complexity of today\u2019s cybersecurity analyst activities makes the need to embrace automation paramount.<\/p>\n\n\n\n<h2 class=\"wp-block-heading has-eigengrau-color has-text-color has-link-color wp-elements-ced96f9b7d6a98bcdd3eb12b751de9b5\" id=\"cybersecurity_is_not_just_a_technology_issue\u2014processes_are_key_\">Cybersecurity is not just a technology issue\u2014processes are key <\/h2>\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-2a9a1b55f183d382677edaf0776c574a\">The most crucial factor in the security operation center (SOC) is having a plan to respond to incidents. Cybersecurity serves the business and it is important to take its mandates into account when creating <a href=\"https:\/\/www.sumologic.com\/glossary\/standard-operating-procedures-sops\/\">standard operating procedures (SOPs)<\/a> for business continuity. Often legacy SOCs fail to assess alerts promptly because there are too many processes to follow and too many tools to manage.<\/p>\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-d86b620a4e7beaa06582cc20fb23b7b4\"><a href=\"https:\/\/www.sumologic.com\/solutions\/cloud-soar\/\">Sumo Logic Cloud SOAR<\/a> (security orchestration, automation and response) accelerates incident response time by operationalizing SOPs and maximizing<a href=\"https:\/\/www.sumologic.com\/blog\/how-soar-improves-soc-team\/\"> overall SOC efficiency<\/a>. <\/p>\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-fcd398de8f408929883aa2a87a9c9902\">The one thing SOC teams need to avoid when facing a potential cyberattack is improvisation.<\/p>\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-0e1ebc5beef6e91fba7e32a14342d10d\">This blog discusses core features of SOAR to enhance collaboration and speed the incident response process, including the new War Room feature that helps capture and detail the specificities of each incident.<\/p>\n\n\n\n<h2 class=\"wp-block-heading has-eigengrau-color has-text-color has-link-color wp-elements-981a06088f3326a2d71a9dd640e6fb07\" id=\"cloud_soar_improves_sops_by_boosting_automation\">Cloud SOAR improves SOPs by boosting automation<\/h2>\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-e9fab54a033ada46794a42bdcc8ef9b1\">Over the years, the types of attacks have increased significantly. Many different technologies are necessary to prevent and respond to threats. SOAR leverages automation in response processes, ingesting alerts generated by different technologies used in the SOC, such as those from <a href=\"https:\/\/www.sumologic.com\/guides\/siem\" data-type=\"resource\" data-id=\"3026\">SIEM<\/a> (security information and event management) solutions.<br><\/p>\n\n\n\n<h3 class=\"wp-block-heading has-eigengrau-color has-text-color has-link-color wp-elements-b28c2a59ec2e06dd00df701fa2df79f5\" id=\"soar_starts_where_siem_ends\">SOAR starts where SIEM ends<br><\/h3>\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-785f6d3bc4c904f3cddabfa2e12cf0d0\"><a href=\"https:\/\/www.sumologic.com\/blog\/soar-starts-where-detection-stops-understanding-the-role-of-soar-in-standard-operating-procedures\/\">SOAR receives alerts and insights from SIEM<\/a>, suggesting to analysts the right processes to activate based on the type of threat. This allows the cyber team to leverage automation for alert enrichment by collecting and organizing data from many different technologies in the case manager. Furthermore, it facilitates analysts&#8217; work by assigning only those tasks where human intervention is essential, leaving the rest to automation.<\/p>\n\n\n\n<h2 class=\"wp-block-heading has-eigengrau-color has-text-color has-link-color wp-elements-33c5df52927a5a9fe59647a347842b81\" id=\"the_secops_dashboard\u2014all_analyst_tasks_in_one_place\">The SecOps dashboard\u2014all analyst tasks in one place<\/h2>\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-929f98040d22d6a1df1b55fb1d163c3e\">The Cloud SOAR SecOps dashboard helps analysts when human interaction is needed. Analysts have all tasks in one place where they can choose whether to complete, assign, close, reassign or decline their automatically assigned actions, user choices and tasks. They can review playbook suggestions and use the <a href=\"https:\/\/www.sumologic.com\/blog\/how-to-make-the-most-out-of-cloud-soars-search-bar-step-by-step-guide\/\">search query bar<\/a> to optimize workflow processes, easily customize the viewing perspective and choose which data they want to see.<br><\/p>\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-722d73355a96057dfe9d5eab3ee93cc3\"><em>The Cloud SOAR SecOps dashboard puts analyst tasks in one place<\/em><br><\/p>\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-b2160484129a82783915e7fd38dcfc63\">Implementing automation in SecOps, especially for time-consuming and low-risk tasks can dramatically improve analyst effectiveness and productivity. At the same time, it is critical to have full visibility into what has been done until the analyst took action. This is why the newly introduced War Room is such an important feature.<br><\/p>\n\n\n\n<h2 class=\"wp-block-heading has-eigengrau-color has-text-color has-link-color wp-elements-12cec50c8c166b514776fad67bc5c770\" id=\"the_role_of_war_room_in_day-to-day_activities\">The role of War Room in day-to-day activities<\/h2>\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-3594138a2adb7505617b430469b9a421\">The goal of Cloud SOAR War Room is to provide a complete and detailed picture of a specific incident process in one single page.. It allows analysts to see all the data collected in a well-structured way so that they can easily make insightful decisions.<br><\/p>\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-5ad9e45d7fa3f5a8bdfd107bc564e589\"><em>War Room timeline<\/em><\/p>\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-88b0f608b978f59531b7e49d43613b5a\">With War Room, the cyber team sees everything that happened in a specific incident in chronological order. Using the familiar concept of a timeline, the War Room shows a detailed view of every relevant event that happened during a specific incident.<\/p>\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-05f1228b8d490fade821d1dee73338b7\">The cyber team can filter the results according to their specific needs and analyze all the information collected and actions performed, including:<br><\/p>\n\n\n\n<ul>\n<li dir=\"ltr\">\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-e3aefb2b05eec689e3e0a29662564ce0\">Incident updates<\/p>\n\n\n\n<\/li>\n<li dir=\"ltr\">\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-aa847bfa684d775e3c73ba846f664139\">Playbooks activated<\/p>\n\n\n\n<\/li>\n<li dir=\"ltr\">\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-d795bceacc756ba56ec84157f6114c9e\">Tasks<\/p>\n\n\n\n<\/li>\n<li dir=\"ltr\">\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-c656b1da96462c87afce2be3a16559fa\">Notes<\/p>\n\n\n\n<\/li>\n<li dir=\"ltr\">\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-148aacafb11b6431b385b0a1f6a20afd\">Entities involved<\/p>\n\n\n\n<\/li>\n<li dir=\"ltr\">\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-e94c6b2bcde0b355a4964f6215996c64\">Attachments<\/p>\n\n\n\n<\/li>\n<li dir=\"ltr\">\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-c34dd2d5a9305fcfe7da8aea9741155e\">Chats<\/p>\n\n\n\n<\/li>\n<\/ul>\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-4516968b5de3f91756366d018146c41f\"><em>War Room filters<\/em><br><\/p>\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-b0c155e93d3690b9b3db39c2587d599b\">War Room entries have been categorized into different types and each type has a corresponding color and bookmark allowing for quick filtering and instant recognition. The entries are listed chronologically in a card format and each card shows relevant information according to the type of entry, displaying the most important content at a glance.<\/p>\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-7b156473a7070d8b0370898c7ccfce10\">Some cards expand details for a deeper analysis. For instance, playbook cards can be expanded to show the actual results of their execution.<\/p>\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-03741202c46cbd4cc00ef3f18240df2a\">It is also possible to add custom events to the War Room that will be classified as notes. Custom events are useful for taking notes on a particular event, allowing information sharing and additional collaboration between investigators.<\/p>\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-8f1c1449e74bae6adb544be26e44370d\">The War Room helps to increase collaboration. From it the cyber team can add notes, set the ordering, activate playbooks, perform tasks, filter results and even export the War Room information .<\/p>\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-1070ef375dfa81b73c7f461f03768595\">A new &#8220;Graph View&#8221; shows the standard timeline format, offering a visual outcome of the incident development.<br><\/p>\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-c4528d4d5a62a218b8f87951ef5f5d47\"><em>War Room Graph View<\/em><\/p>\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-ed97536467703b72ba90b5412269c910\">Cloud SOAR also reduces your incident response time thanks to the following:<br><\/p>\n\n\n\n<ul>\n<li dir=\"ltr\">\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-533d7ad56dfd5190bfd48222ea5f0f3f\"><strong>Flexibility in creating incident response processes. <\/strong>Thanks to the <a href=\"https:\/\/www.sumologic.com\/blog\/uncovering-the-powers-of-cloud-soars-open-integration-framework\/\">Open Integration Framework<\/a>, all <a href=\"https:\/\/www.sumologic.com\/applications\/soar\/\">integrations<\/a> can be created or modified, even independently, and playbooks can be constantly improved.<\/p>\n\n\n\n<\/li>\n<li dir=\"ltr\">\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-4434c13b92952232da5c0e4a323b52ab\"><strong>The easy use of SOPs by analysts<\/strong> who find only high-value tasks in the SecOps dashboard to manage.<\/p>\n\n\n\n<\/li>\n<li dir=\"ltr\">\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-794027899625fdf7920af7d699456bef\"><strong>A powerful case manager with hundreds of custom fields<\/strong> that allow you to store data in an orderly manner.<br><\/p>\n\n\n\n<\/li>\n<\/ul>\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-907ad69f3a44a890d722d27abbb49e15\"><strong>In concert with Cloud SOAR, War Room provides timely visibility of everything<\/strong> that has been done in a single incident and performs other actions directly from it.<\/p>\n\n\n\n<h3 class=\"wp-block-heading has-eigengrau-color has-text-color has-link-color wp-elements-65b026e017862fa86d116c04499e692c\" id=\"flexibility_vs_structured_response_plan_vs_total_control_of_incidents\">Flexibility vs structured response plan vs total control of incidents<\/h3>\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-29721ebced12bae662c1f0e312383c53\">Nowadays it is very complex to handle different types of attacks while managing so many technologies. You need the flexibility to adapt cybersecurity to business processes, a structured response plan that every analyst can follow and a solution that allows easy control of all incidents and actions performed. Cloud SOAR War Room and the other key capabilities give you the overall control of every single incident allowing you to improve the efficiency and the consistency of your cyber team\u2019s activities.<\/p>\n\n\n\n<p class=\"has-delft-blue-color has-text-color has-link-color wp-elements-6078317b842a62fd2616724be838c735\">If you&#8217;d like to see how Sumo Logic Cloud SOAR can improve your team&#8217;s collaboration and reduce incident response time, <a href=\"https:\/\/www.sumologic.com\/request-cloud-soar-demo\/\">request a demo today<\/a>.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div><\/section>\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":238,"featured_media":0,"template":"","meta":{"_acf_changed":false,"show_custom_date":false,"custom_date":"","featured":false,"featured_image":0,"learn_more_label":"","image_alt_text":"","learn_more_type":"","show_popup":false,"learn_more_link_file":0,"event_date":false,"event_start_date":"","event_end_date":"","place_holder_image_url":"","post_reading_time":"4","notification_enabled":false,"notification_text":"","notification_logo":"","notification_expiration_time":0,"is_enable_transparent_header":false,"selected_taxonomy_terms":{"blog-category":[133],"blog-tag":[]},"selected_primary_terms":[],"learn_more_link":[],"featured_page_list":[],"notification_enabled_post_list":[],"_gspb_post_css":"","_relevanssi_hide_post":"","_relevanssi_hide_content":"","_relevanssi_pin_for_all":"","_relevanssi_pin_keywords":"","_relevanssi_unpin_keywords":"","_relevanssi_related_keywords":"","_relevanssi_related_include_ids":"","_relevanssi_related_exclude_ids":"","_relevanssi_related_no_append":"","_relevanssi_related_not_related":"","_relevanssi_related_posts":"4668,71369,71176","_relevanssi_noindex_reason":"","inline_featured_image":false,"footnotes":""},"blog-category":[133],"blog-tag":[],"class_list":["post-5418","blog","type-blog","status-publish","hentry","blog-category-cloud-soar"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.sumologic.com\/wp-json\/wp\/v2\/blog\/5418","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.sumologic.com\/wp-json\/wp\/v2\/blog"}],"about":[{"href":"https:\/\/www.sumologic.com\/wp-json\/wp\/v2\/types\/blog"}],"author":[{"embeddable":true,"href":"https:\/\/www.sumologic.com\/wp-json\/wp\/v2\/users\/238"}],"version-history":[{"count":3,"href":"https:\/\/www.sumologic.com\/wp-json\/wp\/v2\/blog\/5418\/revisions"}],"predecessor-version":[{"id":26808,"href":"https:\/\/www.sumologic.com\/wp-json\/wp\/v2\/blog\/5418\/revisions\/26808"}],"wp:attachment":[{"href":"https:\/\/www.sumologic.com\/wp-json\/wp\/v2\/media?parent=5418"}],"wp:term":[{"taxonomy":"blog-category","embeddable":true,"href":"https:\/\/www.sumologic.com\/wp-json\/wp\/v2\/blog-category?post=5418"},{"taxonomy":"blog-tag","embeddable":true,"href":"https:\/\/www.sumologic.com\/wp-json\/wp\/v2\/blog-tag?post=5418"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}