My organization ran into a similar issue when we were initially deploying SOAR - we think it was due to our notable events having too many characters and then the entire message getting truncated. We ended up creating "One Notable to Rule them All" - just a notable that looks for other notables - it also removes fields we don't care about, ignores all suppressed events, and a few other pieces that make sense for our environment. We then also set the alert actions on this notable itself.
... View more