Loading

Configure access to cases

Elastic Stack Serverless

To access cases in Stack Management, you must have the appropriate Kibana privileges:

Kibana privileges

  • All for the Cases feature under Management.
  • All for the Actions and Connectors feature under Management.
Note

The Actions and Connectors feature privilege is required to create, add, delete, and modify case connectors and to send updates to external systems.

By default, All for the Cases feature includes authority to delete cases and comments, edit case settings, add case comments and attachments, and re-open cases unless you customize the sub-feature privileges.

Kibana privileges

  • All for the Cases feature under Management.
Note

Before a user can be assigned to a case, they must log into Kibana at least once, which creates a user profile.

This privilege is also required to add case actions to rules.

Kibana privileges

  • Read for the Cases feature under Management.
Note

You can customize sub-feature privileges for deleting cases and comments, editing case settings, adding case comments and attachments, and re-opening cases.

Kibana privileges

None for the Cases feature under Management.

For more details, refer to Kibana privileges.

Note

If you are using an on-premises Kibana deployment and you want the email notifications and the external incident management systems to contain links back to Kibana, you must configure the server.publicBaseUrl setting.