I published an article on IBM Security Intelligence on Reducing Dwell Time With Automated Incident Response. The article covers collecting event information, sharing intelligence data and then moving towards automated incident response together with automated digital forensic acquisition (with MIG & GRR).
The incident response orchestration process covers TheHive, MISP, LogicHub and VMRay to extend further on automation.