| navigation_title | Control access | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| mapped_pages | |||||||||||||
| applies_to |
|
||||||||||||
| products |
|
||||||||||||
| description | Create custom roles and configure Kibana feature privileges to control access to cases. |
To manage cases, users need the appropriate {{kib}} feature privileges. You can grant different levels of access depending on what users need to do, from full control over cases to view-only access.
The following table shows the minimum privileges required for each activity. Higher privilege levels include the access shown here. Set Cases privileges under your solution ({{stack-manage-app}}, Security, or {{observability}}). Refer to the following sections for the full breakdown.
| To... | Minimum required privilege |
|---|---|
| View cases | Cases: Read |
| Create and manage cases | Cases: All |
| Be assigned to cases | Cases: All (user must also log in at least once) |
| Manage connectors and push cases externally | Cases: All + {{connectors-feature}}: All (under Management) |
Manage case templates and the field library {applies_to}stack: ga 9.5 {applies_to}serverless: ga |
Cases: All + Manage templates sub-feature privilege |
| Add alerts to cases | Cases: All + alert privileges for your solution (see Give access to add alerts to cases) |
::::{applies-switch}
:::{applies-item} stack: ga
Create or update a role, then set Cases privileges under your solution ({{stack-manage-app}}, Security, or {{observability}}). To grant individual privileges, turn on Customize sub-feature privileges. For details about feature and sub-feature privileges, refer to {{kib}} privileges.
:::
:::{applies-item} serverless: ga
Create a custom role, then set Cases privileges under your solution (Security or {{observability}}). To grant individual privileges, turn on Customize sub-feature privileges.
:::
::::
When Customize sub-feature privileges is on for Cases, you can grant these privileges individually. For details about feature and sub-feature privileges, refer to {{kib}} privileges.
| Privilege | Description |
|---|---|
| Delete | Delete cases and comments. |
| Case settings | Edit case settings. |
| Create comments & attachments | Add comments to cases. |
| Re-open | Re-open closed cases. |
| Assign users | Assign users to cases. |
Manage templates {applies_to}stack: ga 9.5 {applies_to}serverless: ga |
Manage case templates. |
::::{applies-switch}
:::{applies-item} stack: ga
Allfor the Cases feature under the appropriate solution ({{stack-manage-app}}, Security, or {{observability}}). This grants full control over cases, including creating, deleting, and editing case settings. You can turn on Customize sub-feature privileges to limit access.Allfor the {{connectors-feature}} feature under Management. This is required to create, add, delete, and modify connectors that push cases to external systems.
:::
:::{applies-item} serverless: ga
Allfor the Cases feature under the appropriate solution (Security or {{observability}}).Allfor the {{connectors-feature}} feature under Management. This is required to create, add, delete, and modify case connectors and send updates to external systems. :::
::::
::::{applies-switch}
:::{applies-item} stack: ga
All for the Cases feature under the appropriate solution ({{stack-manage-app}}, Security, or {{observability}}).
Users must log in to their deployment at least once before they can be assigned to cases. Logging in creates the required user profile.
:::
:::{applies-item} serverless: ga
All for the Cases feature under the appropriate solution (Security or {{observability}}).
Users must log in to their deployment at least once before they can be assigned to cases. Logging in creates the required user profile. :::
::::
::::{applies-switch}
:::{applies-item} stack: ga
Read for the Cases feature under the appropriate solution ({{stack-manage-app}}, Security, or {{observability}}).
:::
:::{applies-item} serverless: ga
Read for the Cases feature under the appropriate solution (Security or {{observability}}).
:::
::::
stack: ga 9.5
serverless: ga
To create, edit, delete, import, and export case templates and field library entries, grant the following privileges. Users without Manage templates can still select and apply enabled templates when creating or updating a case.
::::{applies-switch}
:::{applies-item} stack: ga
- Set
Allfor the Cases feature under the appropriate solution ({{stack-manage-app}}, Security, or {{observability}}). - Turn on Customize sub-feature privileges.
- Enable Manage templates.
:::
:::{applies-item} serverless: ga
- Set
Allfor the Cases feature under the appropriate solution (Security or {{observability}}). - Turn on Customize sub-feature privileges.
- Enable Manage templates.
:::
::::
::::{applies-switch}
:::{applies-item} { stack: ga 9.4+, serverless: ga }
Allfor the Cases feature under the appropriate solution (Security or {{observability}}).- To work with alerts in cases:
- Security:
ReadorAllfor the Security → Alerts feature. For what each level allows, refer to Detections privileges. - {{observability}}:
Readfor {{observability}}
- Security:
:::
:::{applies-item} stack: ga 9.0-9.3
Allfor the Cases feature under the appropriate solution (Security or {{observability}}).Readfor a solution that has alerts (for example, {{observability}} or Security).
:::
::::
::::{applies-switch}
:::{applies-item} stack: ga
None for the Cases feature under the appropriate solution ({{stack-manage-app}}, Security, or {{observability}}).
:::
:::{applies-item} serverless: ga
None for the Cases feature under the appropriate solution (Security or {{observability}}).
:::
::::