Analyze a case with AI
Send a case to an Elastic Agent Builder chat conversation to summarize it or use it as context for follow-up questions.
Make sure the following requirements are met:
- Elastic Agent Builder must be available, with the Agent chat experience selected.
- At least an Enterprise subscription (Elastic Stack) or the appropriate project feature tier (Serverless).
- The
xpack.cases.chat.enabledsetting must betrue. It'sfalseby default.
To analyze a case, open it from the Cases page and use one of the following actions in the case details header:
- Add to chat: Opens a new Elastic Agent Builder conversation with the current case attached as context. You send the first message when you're ready.
- Summarize case: Opens a conversation with the case attached and a pre-filled prompt that asks the agent to summarize the case and suggest next steps.
The attached context includes the following case details:
- Case ID
- Title
- Description
- Status
- Severity
- Tags
- Assignees
- Category
- Created and updated timestamps
- Alert, comment, attachment, and observable counts
- Connector name
- A link back to the case
After a case is attached, you can ask the agent to act on it directly from the conversation. For example, you can:
- Add case comments. For example, after the agent summarizes a case, you can ask it to add that summary as a comment.
- Update case metadata, such as the status, severity, tags, category, title, and description.
- Change the assignees.
- Add attachments, such as alerts, events, or observables.
If you keep the chat open, the case page updates in real time to show any changes the agent makes.