elastic / elastic/docs-content
[Internal]: [Feature][Cases] Adding source to case activity
- Dominant language
- No language data
- Stars
- 47
- Forks
- 261
- Avg merge
- 3d 12h
- Merged PRs (30d)
- 116
Description
### Description
User actions in cases are now enriched with source, which indicates how the actions are initiated. The sources are: agent, workflow, API, rule, attack discovery and user.
https://github.com/elastic/kibana/pull/287149 implemented the UI display, a follow up PR will add a filter to let users filter activity by source
### Resources
Epic: https://github.com/elastic/security-team/issues/18863 https://github.com/elastic/security-team/issues/19037
PR: https://github.com/elastic/kibana/pull/287149
### Which deployment methods does this change impact?
Elastic On-Prem and Cloud (all)
### Feature differences
No difference
### What Elastic Stack release is this request related to?
9.6
### Serverless release
The week of September 21, 2026
### Collaboration model
Unknown
### Point of contact.
**Main contact:** @christineweng
**Stakeholders:**PM @melissaburpo
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.