[Request] [8.18, 9.0, and Serverless] Observables can be added to cases #6395
Labels
blocked
An issue that's currently blocked because it’s pending info or action from stakeholders.
Docset: ESS
Issues that apply to docs in the Stack release
Docset: Serverless
Issues for Serverless Security
Effort: Medium
Issues that take moderate but not substantial time to complete
Feature: Cases
Cases issues
Priority: High
Issues that are time-sensitive and/or are of high customer importance
Team: Threat Hunting
Formerly Data Visibility
v8.18.0
v9.0.0
Description
Users can associate observables with cases for better tracking and analysis in incident response workflows. This improves investigative efficiency by correlating observables across multiple cases.
Misc. notes:
Background & resources
Which documentation set does this change impact?
ESS and serverless
ESS updates are below. The Serverless updates will be the same.
Changes to the Configure case settings page:
Changes to the Open and manage cases page:
In the Manage existing cases section:
ESS release
8.18 and 9.0
Serverless release
January 7, 2025
Feature differences
N/A
API docs impact
N/A
Prerequisites, privileges, feature flags
ESS license - TBD
Serverless feature tier - Essentials
The text was updated successfully, but these errors were encountered: