Create a test case

Supported in:

A test case lets you treat a case like it's in a sandbox: any actions you perform on its entities don't influence entities in other cases. Test cases only contain the alert that was created in the event and uses existing data to populate it. You can use a test case to run the playbook simulator on or test in the IDE page.

To create a test case, follow these steps:

  1. In the platform, go to the Cases page.
  2. Drill down to the required case and go to the Alert tab.
  3. Click more_vert Alert Options on the right side of the Alert tab.
  4. Click Ingest alert as test case in the Alert Options menu.
  5. Select the required environment and click Simulate.
  6. Refresh the page. A test case appears in the Cases Queue or in the List View table. It's marked with the label Test in the top right corner of the case card. The test case contains only one alert.

You can now use this test case in the playbook simulator, or in the IDE testing page. Note that updating entity properties on a test case won't influence the entity outside of the test case.

Need more help? Get answers from Community members and Google SecOps professionals.