Skip to content

[UI copy]: Cases auto-extract observables #3159

@christineweng

Description

@christineweng

Description

Add to new case

Left: When user adds an alert to a new case, and select both sync alerts and auto-extract observables

The alert statuses are synched with the case status. Observables are extracted and added to the case

Right: When the observables for the case reaches maximum (currently 50, screenshot showing 1 as example)

The meximum number of observables is [MAX_NUM]. Some observables were not added
Image Image

Case detail page

Default observables extraction modal: this modal shows what fields are automatically extracted if the toggle is on

These ECS fields are automatically extracted if auto-extract observable is turned on.
Image

Manually add observables: placeholder texts were added

Image

Related links / assets

Please include each of the following, if applicable:
Figma link(s): https://www.figma.com/design/aNDZJVpdAWGQD9j2gkuXKE/-one-Cases--Cases-in-Solutions?node-id=1127-38062&t=8P3Et9nDJcQdwQkf-1
Github epic link(s): https://github.com/elastic/security-team/issues/13709
Github issue link(s): elastic/kibana#233027
How to find the text in a production environment:
Testing environment information:
NOTE: To keep sensitive information such as credentials secure, do not include it in this form.

Which product area does this mainly concern?

Security solution

Collaborators

PM: @melissaburpo
Designer: @maciejforcone
Developer: @christineweng
Others (if applicable):

Timeline / deliverables

Around 9/6 will be ideal. Will share cloud env on slack

Metadata

Metadata

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions