Automating detection tuning requests with Kibana cases
ID: 203643ba-dac5-5dcf-8695-3e0887bca790
STIX ID: report--203643ba-dac5-5dcf-8695-3e0887bca790
Feed Name: Elastic Security Labs
This article outlines how to build an automated, one-click detection tuning request workflow in Elastic Security using Kibana Cases with custom fields (text/toggle), runtime fields to parse case metadata, and Elasticsearch queries to find recently updated cases and retrieve attached alerts. It walks through creating custom fields, mapping them via runtime scripts, querying the .kibana_alerting_cases and .siem-signals* indices, deduplicating alerts by rule, and integrating with external systems (e.g., GitHub Issues, Slack) to open or update tuning tickets and notify detection engineers—closing the analyst–engineer feedback loop, reducing false positives, and improving SOC efficiency.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
