Skip to content

[Internal]: Add auto-push case option to case connector #4756

@janmonschke

Description

@janmonschke

Description

Currently, there is a functional gap between our Detection Rule actions and our Case external integrations.

When configuring a Detection Rule, a user can:

  1. Create an Elastic Case: This creates a case object in Elastic Security.
  2. Use a Connector Action (e.g., IBM Resilient, Jira): This sends alert data to the external system, creating an incident there.

The Problem: Option 2 creates a forked workflow. The incident in the external system is not linked to the Elastic Case created in Option 1. They exist as two separate entities.

This feature request is to add a configuration option within the Case Action settings of a Detection Rule to automatically trigger the "Push" logic immediately after the case is created.

Image

Resources

PR: elastic/kibana#249251

Product ticket: https://github.com/elastic/security-team/issues/15197

Which documentation set does this change impact?

Elastic On-Prem and Cloud (all)

Feature differences

none

What release is this request related to?

9.2

Serverless release

The week of January 26th Feb 2nd

Collaboration model

The documentation team

Point of contact.

Main contact: @janmonschke

Stakeholders: @melissaburpo

Metadata

Metadata

Labels

Team:ExperienceIssues owned by the Experience Docs Team

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions