Improved Observable Extraction and Management for Cases
- Dominant language
- No language data
- Stars
- 6
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Description
This update completes observable extraction in Cases with configuration controls and quality-of-life improvements for teams relying on it at scale.
**Value proposition**
In 9.5, observable extraction expanded to work across all case creation methods: UI, API, Workflows, and detection rules. What remains is giving administrators and analysts direct control over the feature: setting space-level extraction defaults so automation doesn't require per-request opt-in, configuring which fields are extracted to reduce noise, triggering extraction retroactively on existing cases, and managing observables in bulk. Without these controls, teams running high-volume SOC workflows encounter noisy observable lists that degrade cross-case correlation and require manual cleanup.
**Expected outcome**
* Improve the accuracy of cross-case correlation by allowing admins to configure which fields are extracted and suppress low-fidelity indicators.
* Eliminate per-request opt-in for API and automation workflows through space-level extraction defaults.
* Manage observables more efficiently with bulk delete and on-demand re-extraction for existing cases.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.