elastic / elastic/docs-content

[Internal]: [Feature][Cases] Adding source to case activity

Open
#8,266 1 comment 0 reactions 1 assignee Claimed by @nastasha-solomon View on GitHub
Team:SKI
Dominant language
No language data
Stars
47
Forks
261
Avg merge
3d 12h
Merged PRs (30d)
116

Description

### Description

User actions in cases are now enriched with source, which indicates how the actions are initiated. The sources are: agent, workflow, API, rule, attack discovery and user.

https://github.com/elastic/kibana/pull/287149 implemented the UI display, a follow up PR will add a filter to let users filter activity by source

Image

### Resources

Epic: https://github.com/elastic/security-team/issues/18863 https://github.com/elastic/security-team/issues/19037
PR: https://github.com/elastic/kibana/pull/287149

### Which deployment methods does this change impact?

Elastic On-Prem and Cloud (all)

### Feature differences

No difference

### What Elastic Stack release is this request related to?

9.6

### Serverless release

The week of September 21, 2026

### Collaboration model

Unknown

### Point of contact.

**Main contact:** @christineweng

**Stakeholders:**PM @melissaburpo

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.