logo

Automating detection tuning requests with Kibana cases

ID: 203643ba-dac5-5dcf-8695-3e0887bca790

STIX ID: report--203643ba-dac5-5dcf-8695-3e0887bca790

Feed Name: Elastic Security Labs

Date Published: 2025-12-05

Date Updated: 2026-04-27

...
...

This article outlines how to build an automated, one-click detection tuning request workflow in Elastic Security using Kibana Cases with custom fields (text/toggle), runtime fields to parse case metadata, and Elasticsearch queries to find recently updated cases and retrieve attached alerts. It walks through creating custom fields, mapping them via runtime scripts, querying the .kibana_alerting_cases and .siem-signals* indices, deduplicating alerts by rule, and integrating with external systems (e.g., GitHub Issues, Slack) to open or update tuning tickets and notify detection engineers—closing the analyst–engineer feedback loop, reducing false positives, and improving SOC efficiency.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.