Loading

Analyze a case with AI

Send a case to an Elastic Agent Builder chat conversation to summarize it or use it as context for follow-up questions.

Make sure the following requirements are met:

  • Elastic Agent Builder must be available, with the Agent chat experience selected.
  • At least an Enterprise subscription (Elastic Stack) or the appropriate project feature tier (Serverless).
  • The xpack.cases.chat.enabled setting must be true. It's false by default.

To analyze a case, open it from the Cases page and use one of the following actions in the case details header:

  • Add to chat: Opens a new Elastic Agent Builder conversation with the current case attached as context. You send the first message when you're ready.
  • Summarize case: Opens a conversation with the case attached and a pre-filled prompt that asks the agent to summarize the case and suggest next steps.

The attached context includes the following case details:

  • Case ID
  • Title
  • Description
  • Status
  • Severity
  • Tags
  • Assignees
  • Category
  • Created and updated timestamps
  • Alert, comment, attachment, and observable counts
  • Connector name
  • A link back to the case

After a case is attached, you can ask the agent to act on it directly from the conversation. For example, you can:

  • Add case comments. For example, after the agent summarizes a case, you can ask it to add that summary as a comment.
  • Update case metadata, such as the status, severity, tags, category, title, and description.
  • Change the assignees.
  • Add attachments, such as alerts, events, or observables.

If you keep the chat open, the case page updates in real time to show any changes the agent makes.