-
Hi, If I create a case and set assignee + status, is it possible to somehow search these cases from elastc dev tools -> console? So far I can find all the events with no problem but not the so_case.assigneeId, so_case.status values. BR |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 10 replies
-
Or is it possible to query from so-case? I'm guessing the data is there but I just don't know how to approach it. |
Beta Was this translation helpful? Give feedback.
-
The main Cases page shows the You should be able to click on a value in those columns to get a context menu that allows you to include, exclude, etc. as described on the Dashboards page: If you need even more features in the main Cases interface, you can enable advanced interface features: |
Beta Was this translation helpful? Give feedback.
The main Cases page shows the
so_case.status
andso_case.assigneeId
columns:You should be able to click on a value in those columns to get a context menu that allows you to include, exclude, etc. as described on the Dashboards page:
https://docs.securityonion.net/en/2.3/dashboards.html#context-menu
If you need even more features in the main Cases interface, you can enable advanced interface features:
https://docs.securityonion.net/en/2.3/cases.html#options