Skip to content

Commit 01cec65

Browse files
case requirements
1 parent d8e56bb commit 01cec65

File tree

5 files changed

+9
-89
lines changed

5 files changed

+9
-89
lines changed

raw-migrated-files/docs-content/serverless/security-cases-requirements.md

Lines changed: 0 additions & 26 deletions
This file was deleted.

raw-migrated-files/toc.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -238,7 +238,6 @@ toc:
238238
- file: docs-content/serverless/security-blocklist.md
239239
- file: docs-content/serverless/security-building-block-rules.md
240240
- file: docs-content/serverless/security-cases-overview.md
241-
- file: docs-content/serverless/security-cases-requirements.md
242241
- file: docs-content/serverless/security-cases-settings.md
243242
- file: docs-content/serverless/security-cloud-native-security-overview.md
244243
- file: docs-content/serverless/security-cloud-posture-dashboard-dash-cspm.md

solutions/security/investigate/cases-requirements.md

Lines changed: 9 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -4,35 +4,24 @@ mapped_urls:
44
- https://www.elastic.co/guide/en/serverless/current/security-cases-requirements.html
55
---
66

7-
# Cases requirements
8-
9-
% What needs to be done: Align serverless/stateful
10-
11-
% Use migrated content from existing pages that map to this page:
12-
13-
% - [x] ./raw-migrated-files/security-docs/security/case-permissions.md
14-
% - [ ] ./raw-migrated-files/docs-content/serverless/security-cases-requirements.md
15-
16-
You can create roles and define feature privileges at different levels to manage feature access in {{kib}}. {{kib}} privileges grant access to features within a specified {{kib}} space, and you can grant full or partial access. For more information, refer to [{{kib}} privileges](/deploy-manage/users-roles/cluster-or-deployment-auth/defining-roles.md#adding_kibana_privileges).
7+
# Cases requirements [security-cases-requirements]
178

189
::::{note}
19-
To send cases to external systems, you need the [appropriate license](https://www.elastic.co/subscriptions).
10+
- To send cases to external systems, ensure you have the appropriate [{{stack}} subscription](https://www.elastic.co/pricing) or [{{serverless-short}} project tier](../../../deploy-manage/deploy/elastic-cloud/project-settings.md).
2011

21-
If you are using an on-premises {{kib}} deployment and want the email notifications and the external incident management systems to contain links back to {{kib}}, you must configure the [server.publicBaseUrl](/deploy-manage/deploy/self-managed/configure.md#server-publicBaseUrl) setting.
12+
- Certain subscriptions and privileges might be required to manage case attachments. For example in {{stack}}, to add alerts to cases, you must have privileges for [managing alerts](/solutions/security/detect-and-alert/detections-requirements.md#enable-detections-ui). In {{serverless-short}}, you need the Security Analytics Complete [project feature](../../../deploy-manage/deploy/elastic-cloud/project-settings.md).
2213

14+
- If you are using an on-premises {{kib}} deployment and want the email notifications and the external incident management systems to contain links back to {{kib}}, you must configure the [server.publicBaseUrl](/deploy-manage/deploy/self-managed/configure.md#server-publicBaseUrl) setting.
2315
::::
2416

2517

26-
::::{important}
27-
Certain subscriptions and privileges might be required to manage case attachments. For example, to add alerts to cases, you must have privileges for [managing alerts](/solutions/security/detect-and-alert/detections-requirements.md#enable-detections-ui).
28-
::::
29-
18+
To grant access to cases in a custom role, set the privileges for the **Cases** and **{{connectors-feature}}** features as follows:
3019

31-
To grant access to cases, set the privileges for the **Cases** and **{{connectors-feature}}** features as follows:
20+
% Management might be called Stack Management in Serverless.
3221

3322
| Action | {{kib}} Privileges |
3423
| --- | --- |
35-
| Give full access to manage cases and settings | * **All** for the **Cases** feature under **Security**<br>* **All*** for the **{{connectors-feature}}** feature under **Management**<br><br>::::{note} <br>Roles without ***All** privileges for the **{{connectors-feature}}** feature cannot create, add, delete, or modify case connectors.<br><br>By default, **All** for the **Cases** feature allows you to delete cases, delete alerts and comments from cases, and edit case settings. You can customize the sub-feature privileges to limit feature access.<br><br>::::<br><br> |
36-
| Give assignee access to cases | **All** for the **Cases** feature under **Security**<br><br>::::{note} <br>Before a user can be assigned to a case, they must log into {{kib}} at least once, which creates a user profile.<br>::::<br><br> |
37-
| Give view-only access for cases | **Read** for the **Security** feature and **All** for the **Cases** feature<br><br>::::{note} <br>You can customize the sub-feature privileges to allow access to deleting cases, deleting alerts and comments from cases, viewing or editing case settings, adding case comments and attachments, and re-opening cases.<br>::::<br><br> |
24+
| Give full access to manage cases and settings | - **All** for the **Cases** feature under **Security**<br> - **All*** for the **{{connectors-feature}}** feature under **Management**<br><br>**Note:** Roles without **All** privileges for the **{{connectors-feature}}** feature cannot create, add, delete, or modify case connectors. By default, **All** for the **Cases** feature allows you to delete cases, delete alerts and comments from cases, and edit case settings. You can customize the sub-feature privileges to limit feature access.<br><br><br><br> |
25+
| Give assignee access to cases | **All** for the **Cases** feature under **Security**<br><br>**Note:** Before a user can be assigned to a case, they must log into {{kib}} at least once, which creates a user profile. <br><br> |
26+
| Give view-only access for cases | **Read** for the **Security** feature and **All** for the **Cases** feature<br><br> **Note:** You can customize the sub-feature privileges to allow access to deleting cases, deleting alerts and comments from cases, viewing or editing case settings, adding case comments and attachments, and re-opening cases. <br><br> |
3827
| Revoke all access to cases | **None** for the **Cases** feature under **Security** |

solutions/security/investigate/notes.md

Lines changed: 0 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -6,19 +6,6 @@ mapped_urls:
66

77
# Notes [security-add-manage-notes]
88

9-
% What needs to be done: Lift-and-shift
10-
11-
% Use migrated content from existing pages that map to this page:
12-
13-
% - [x] ./raw-migrated-files/security-docs/security/add-manage-notes.md
14-
% - [ ] ./raw-migrated-files/docs-content/serverless/security-add-manage-notes.md
15-
16-
% Internal links rely on the following IDs being on this page (e.g. as a heading ID, paragraph ID, etc):
17-
18-
$$$manage-notes$$$
19-
20-
$$$notes-alerts-events$$$
21-
229
Incorporate notes into your investigative workflows to coordinate responses, conduct threat hunting, and share investigative findings. You can attach notes to alerts, events, and Timelines and manage them from the **Notes** page.
2310

2411
::::{note}

solutions/security/investigate/open-manage-cases.md

Lines changed: 0 additions & 29 deletions
Original file line numberDiff line numberDiff line change
@@ -6,35 +6,6 @@ mapped_urls:
66

77
# Open and manage cases [security-cases-open-manage]
88

9-
% What needs to be done: Align serverless/stateful
10-
11-
% Use migrated content from existing pages that map to this page:
12-
13-
% - [x] ./raw-migrated-files/security-docs/security/cases-open-manage.md
14-
% - [ ] ./raw-migrated-files/docs-content/serverless/security-cases-open-manage.md
15-
16-
% Internal links rely on the following IDs being on this page (e.g. as a heading ID, paragraph ID, etc):
17-
18-
$$$cases-ui-open$$$
19-
20-
$$$cases-add-files$$$
21-
22-
$$$cases-add-observables$$$
23-
24-
$$$cases-copy-case-uuid$$$
25-
26-
$$$cases-examine-alerts$$$
27-
28-
$$$cases-export$$$
29-
30-
$$$cases-import$$$
31-
32-
$$$cases-lens-visualization$$$
33-
34-
$$$cases-manage-comments$$$
35-
36-
$$$cases-summary$$$
37-
389
You can create and manage cases using the UI or the [cases API](https://www.elastic.co/docs/api/doc/kibana/group/endpoint-cases).
3910

4011

0 commit comments

Comments
 (0)