You can define templates for recurring emails, so that they can be sent by
scripts and can be also sent automatically with playbooks.
To create a new email template:
Navigate to Settings > Environments > Email templates.
Click add on the top right of
the screen.
Enter in the Email message as well as name and environment. Note that this
email template is capable of extracting information from
cases/events/entities and more that are available in the Google Security Operations case
using the Placeholder. In this picture, you can see "Case.Name"
inside square brackets, which will get the name of the case in which the
email action is taken.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-08-29 UTC."],[[["\u003cp\u003eEmail templates can be created for recurring emails to be sent by scripts or automatically with playbooks.\u003c/p\u003e\n"],["\u003cp\u003eTemplates are defined within the Settings, under Environments and then Email templates.\u003c/p\u003e\n"],["\u003cp\u003eWhen creating a template you need to enter the Email message, name, and environment.\u003c/p\u003e\n"],["\u003cp\u003ePlaceholders can be used in the message body, allowing for information extraction from cases, events, entities, etc.\u003c/p\u003e\n"]]],[],null,["# Create Email Templates\n======================\n\nSupported in: \nGoogle secops [SOAR](/chronicle/docs/secops/google-secops-soar-toc) \n\nYou can define templates for recurring emails, so that they can be sent by\nscripts and can be also sent automatically with playbooks.\n\n\nTo create a new email template:\n\n1. Navigate to Settings \\\u003e Environments \\\u003e Email templates.\n2. Click add on the top right of the screen.\n3. Enter in the Email message as well as name and environment. Note that this email template is capable of extracting information from cases/events/entities and more that are available in the Google Security Operations case using the Placeholder. In this picture, you can see \"Case.Name\" inside square brackets, which will get the name of the case in which the email action is taken. [](/static/chronicle/images/soar/emailtemplate.png)\n4. Click Add.\n\n**Need more help?** [Get answers from Community members and Google SecOps professionals.](https://security.googlecloudcommunity.com/google-security-operations-2)"]]