You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
You can create roles and define feature privileges at different levels to manage feature access in {{kib}}. {{kib}} privileges grant access to features within a specified {{kib}} space, and you can grant full or partial access. For more information, refer to [{{kib}} privileges](/deploy-manage/users-roles/cluster-or-deployment-auth/defining-roles.md#adding_kibana_privileges).
To send cases to external systems, you need the [appropriate license](https://www.elastic.co/subscriptions).
10
+
-To send cases to external systems, ensure you have the appropriate [{{stack}} subscription](https://www.elastic.co/pricing) or [{{serverless-short}} project tier](../../../deploy-manage/deploy/elastic-cloud/project-settings.md).
20
11
21
-
If you are using an on-premises {{kib}} deployment and want the email notifications and the external incident management systems to contain links back to {{kib}}, you must configure the [server.publicBaseUrl](/deploy-manage/deploy/self-managed/configure.md#server-publicBaseUrl) setting.
12
+
- Certain subscriptions and privileges might be required to manage case attachments. For example in {{stack}}, to add alerts to cases, you must have privileges for [managing alerts](/solutions/security/detect-and-alert/detections-requirements.md#enable-detections-ui). In {{serverless-short}}, you need the Security Analytics Complete [project feature](../../../deploy-manage/deploy/elastic-cloud/project-settings.md).
22
13
14
+
- If you are using an on-premises {{kib}} deployment and want the email notifications and the external incident management systems to contain links back to {{kib}}, you must configure the [server.publicBaseUrl](/deploy-manage/deploy/self-managed/configure.md#server-publicBaseUrl) setting.
23
15
::::
24
16
25
17
26
-
::::{important}
27
-
Certain subscriptions and privileges might be required to manage case attachments. For example, to add alerts to cases, you must have privileges for [managing alerts](/solutions/security/detect-and-alert/detections-requirements.md#enable-detections-ui).
28
-
::::
29
-
18
+
To grant access to cases in a custom role, set the privileges for the **Cases** and **{{connectors-feature}}** features as follows:
30
19
31
-
To grant access to cases, set the privileges for the **Cases** and **{{connectors-feature}}** features as follows:
20
+
% Management might be called Stack Management in Serverless.
32
21
33
22
| Action | {{kib}} Privileges |
34
23
| --- | --- |
35
-
| Give full access to manage cases and settings |***All** for the **Cases** feature under **Security**<br>***All*** for the **{{connectors-feature}}** feature under **Management**<br><br>::::{note} <br>Roles without ***All** privileges for the **{{connectors-feature}}** feature cannot create, add, delete, or modify case connectors.<br><br>By default, **All** for the **Cases** feature allows you to delete cases, delete alerts and comments from cases, and edit case settings. You can customize the sub-feature privileges to limit feature access.<br><br>::::<br><br> |
36
-
| Give assignee access to cases |**All** for the **Cases** feature under **Security**<br><br>::::{note} <br>Before a user can be assigned to a case, they must log into {{kib}} at least once, which creates a user profile.<br>::::<br><br> |
37
-
| Give view-only access for cases |**Read** for the **Security** feature and **All** for the **Cases** feature<br><br>::::{note} <br>You can customize the sub-feature privileges to allow access to deleting cases, deleting alerts and comments from cases, viewing or editing case settings, adding case comments and attachments, and re-opening cases.<br>::::<br><br> |
24
+
| Give full access to manage cases and settings |-**All** for the **Cases** feature under **Security**<br> - **All*** for the **{{connectors-feature}}** feature under **Management**<br><br>**Note:**Roles without **All** privileges for the **{{connectors-feature}}** feature cannot create, add, delete, or modify case connectors.By default, **All** for the **Cases** feature allows you to delete cases, delete alerts and comments from cases, and edit case settings. You can customize the sub-feature privileges to limit feature access.<br><br><br><br> |
25
+
| Give assignee access to cases |**All** for the **Cases** feature under **Security**<br><br>**Note:**Before a user can be assigned to a case, they must log into {{kib}} at least once, which creates a user profile.<br><br> |
26
+
| Give view-only access for cases |**Read** for the **Security** feature and **All** for the **Cases** feature<br><br>**Note:**You can customize the sub-feature privileges to allow access to deleting cases, deleting alerts and comments from cases, viewing or editing case settings, adding case comments and attachments, and re-opening cases.<br><br> |
38
27
| Revoke all access to cases |**None** for the **Cases** feature under **Security**|
% Internal links rely on the following IDs being on this page (e.g. as a heading ID, paragraph ID, etc):
17
-
18
-
$$$manage-notes$$$
19
-
20
-
$$$notes-alerts-events$$$
21
-
22
9
Incorporate notes into your investigative workflows to coordinate responses, conduct threat hunting, and share investigative findings. You can attach notes to alerts, events, and Timelines and manage them from the **Notes** page.
0 commit comments