Skip to content

Commit fa48419

Browse files
Cases and case settings
1 parent 01cec65 commit fa48419

File tree

5 files changed

+8
-213
lines changed

5 files changed

+8
-213
lines changed

raw-migrated-files/docs-content/serverless/security-cases-overview.md

Lines changed: 0 additions & 21 deletions
This file was deleted.

raw-migrated-files/docs-content/serverless/security-cases-settings.md

Lines changed: 0 additions & 150 deletions
This file was deleted.

raw-migrated-files/toc.yml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -237,8 +237,6 @@ toc:
237237
- file: docs-content/serverless/security-benchmark-rules.md
238238
- file: docs-content/serverless/security-blocklist.md
239239
- file: docs-content/serverless/security-building-block-rules.md
240-
- file: docs-content/serverless/security-cases-overview.md
241-
- file: docs-content/serverless/security-cases-settings.md
242240
- file: docs-content/serverless/security-cloud-native-security-overview.md
243241
- file: docs-content/serverless/security-cloud-posture-dashboard-dash-cspm.md
244242
- file: docs-content/serverless/security-cloud-posture-dashboard-dash-kspm.md

solutions/security/investigate/cases.md

Lines changed: 2 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -4,14 +4,7 @@ mapped_urls:
44
- https://www.elastic.co/guide/en/serverless/current/security-cases-overview.html
55
---
66

7-
# Cases
8-
9-
% What needs to be done: Align serverless/stateful
10-
11-
% Use migrated content from existing pages that map to this page:
12-
13-
% - [x] ./raw-migrated-files/security-docs/security/cases-overview.md
14-
% - [ ] ./raw-migrated-files/docs-content/serverless/security-cases-overview.md
7+
# Cases [security-cases-overview]
158

169
Collect and share information about security issues by opening a case in {{elastic-sec}}. Cases allow you to track key investigation details, collect alerts in a central location, and more. The {{elastic-sec}} UI provides several ways to create and manage cases. Alternatively, you can use the [cases API](https://www.elastic.co/docs/api/doc/kibana/group/endpoint-cases) to perform the same tasks.
1710

@@ -30,7 +23,7 @@ You can also send cases to these external systems by [configuring external conne
3023
:::
3124

3225
::::{note}
33-
From {{elastic-sec}}, you cannot access cases created in {{observability}} or Stack Management.
26+
From {{elastic-sec}} in the {{stack}}, you cannot access cases created in {{observability}} or Stack Management.
3427
::::
3528

3629

solutions/security/investigate/configure-case-settings.md

Lines changed: 6 additions & 31 deletions
Original file line numberDiff line numberDiff line change
@@ -4,42 +4,17 @@ mapped_urls:
44
- https://www.elastic.co/guide/en/serverless/current/security-cases-settings.html
55
---
66

7-
# Configure case settings
7+
# Configure case settings [security-cases-settings]
88

9-
% What needs to be done: Align serverless/stateful
10-
11-
% Use migrated content from existing pages that map to this page:
12-
13-
% - [x] ./raw-migrated-files/security-docs/security/cases-manage-settings.md
14-
% - [ ] ./raw-migrated-files/docs-content/serverless/security-cases-settings.md
15-
16-
% Internal links rely on the following IDs being on this page (e.g. as a heading ID, paragraph ID, etc):
17-
18-
$$$cases-templates$$$
19-
20-
$$$cases-ui-custom-fields$$$
21-
22-
$$$cases-ui-integrations$$$
23-
24-
$$$cases-observable-types$$$
25-
26-
$$$security-cases-settings-templates$$$
27-
28-
$$$security-cases-settings-custom-fields$$$
29-
30-
$$$security-cases-observable-types$$$
31-
32-
33-
34-
To change case closure options, add custom fields, templates, and connectors for external incident management systems, and create custom observable types, find **Cases** in the navigation menu or search for `Security/Cases` by using the [global search field](/explore-analyze/find-and-organize/find-apps-and-objects.md), then click **Settings**.
9+
To change case closure options, add custom fields, templates, and connectors for external incident management systems, and create custom observable types. In the {{stack}}, find **Cases** in the navigation menu or search for `Security/Cases` by using the [global search field](/explore-analyze/find-and-organize/find-apps-and-objects.md), then click **Settings**. In {{serverless-short}}, you can access case settings in an {{elastic-sec}} project, go to **Cases****Settings**.
3510

3611
:::{image} ../../../images/security-cases-settings.png
3712
:alt: Shows the case settings page
3813
:class: screenshot
3914
:::
4015

4116
::::{note}
42-
To view and change case settings, you must have the appropriate {{kib}} feature privileges. Refer to [Cases requirements](/solutions/security/investigate/cases-requirements.md).
17+
On {{stack}}, view and change case settings, you must have the appropriate {{kib}} feature privileges. Refer to [Cases requirements](/solutions/security/investigate/cases-requirements.md).
4318
::::
4419

4520

@@ -48,7 +23,7 @@ To view and change case settings, you must have the appropriate {{kib}} feature
4823

4924
If you close cases in your external incident management system, the cases will remain open in {{elastic-sec}} until you close them manually.
5025

51-
To close cases when they are sent to an external system, select **Automatically close cases when pushing new incident to external system**.
26+
To close cases when they are sent to an external system, select the option to automatically close cases when pushing new incident to external system.
5227

5328

5429
## External incident management systems [cases-ui-integrations]
@@ -66,7 +41,7 @@ You can push {{elastic-sec}} cases to these third-party systems:
6641
To push cases, you need to create a connector, which stores the information required to interact with an external system. After you have created a connector, you can set {{elastic-sec}} cases to automatically close when they are sent to external systems.
6742

6843
::::{important}
69-
To create connectors and send cases to external systems, you need the [appropriate license](https://www.elastic.co/subscriptions), and your role needs **All** privileges for the **Action and Connectors** feature. For more information, refer to [Cases requirements](/solutions/security/investigate/cases-requirements.md).
44+
To create connectors and send cases to external systems, ensure you have the appropriate role privileges and [{{stack}} subscription](https://www.elastic.co/pricing) or [{{serverless-short}} project tier](../../../deploy-manage/deploy/elastic-cloud/project-settings.md). For more information, refer to [Cases requirements](/solutions/security/investigate/cases-requirements.md).
7045
::::
7146

7247

@@ -154,7 +129,7 @@ If you update or delete templates, existing cases are unaffected.
154129
## Observable types [cases-observable-types]
155130

156131
::::{admonition} Requirements
157-
To use observables, you must have a [Platinum subscription](https://www.elastic.co/pricing) or higher.
132+
Ensure you have the appropriate [{{stack}} subscription](https://www.elastic.co/pricing) or [{{serverless-short}} project tier](../../../deploy-manage/deploy/elastic-cloud/project-settings.md).
158133

159134
::::
160135

0 commit comments

Comments
 (0)