elastic / elastic/roadmap

Improved Observable Extraction and Management for Cases

Open
#277 0 comments 0 reactions 0 assignees View on GitHub
product-area:security
Dominant language
No language data
Stars
6
Forks
1
PR merge metrics
No merged PRs in 30d

Description

This update completes observable extraction in Cases with configuration controls and quality-of-life improvements for teams relying on it at scale.

**Value proposition**

In 9.5, observable extraction expanded to work across all case creation methods: UI, API, Workflows, and detection rules. What remains is giving administrators and analysts direct control over the feature: setting space-level extraction defaults so automation doesn't require per-request opt-in, configuring which fields are extracted to reduce noise, triggering extraction retroactively on existing cases, and managing observables in bulk. Without these controls, teams running high-volume SOC workflows encounter noisy observable lists that degrade cross-case correlation and require manual cleanup.

**Expected outcome**

* Improve the accuracy of cross-case correlation by allowing admins to configure which fields are extracted and suppress low-fidelity indicators.
* Eliminate per-request opt-in for API and automation workflows through space-level extraction defaults.
* Manage observables more efficiently with bulk delete and on-demand re-extraction for existing cases.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.