Keep SOC investigations organized in one case queue.
security case management
Creates, searches, updates, and manages Elastic Security SOC cases through the Kibana Cases API.
When to use it
Use it to create, find, review, annotate, attach alerts to, or update security cases.
Give it a case-management request; it creates, finds, annotates, attaches alerts to, lists, or updates Kibana cases.
This skill
Kibana
Creates and updates Kibana cases (irreversible)
npm
Installs the skill dependencies
Requires Node.js 22 or newer.
Requires network access to a Kibana deployment providing Elastic Security cases.
Reads a Kibana API key from the environment as one authentication option.
Reads the Kibana username from the environment for basic authentication, paired with KIBANA_PASSWORD.