Analyze a case with AI

Send a case to an Elastic Agent Builder chat conversation to summarize it or use it as context for follow-up questions.

Make sure the following requirements are met:

  • Elastic Agent Builder must be available, with the Agent chat experience selected.
  • At least an Enterprise subscription (Elastic Stack) or the appropriate project feature tier (Serverless).
  • The xpack.cases.chat.enabled setting must be true. It's false by default.

To analyze a case, open it from the Cases page and use one of the following actions in the case details header:

  • Add to chat: Opens a new Elastic Agent Builder conversation with the current case attached as context. You send the first message when you're ready.
  • Summarize case: Opens a conversation with the case attached and a pre-filled prompt that asks the agent to summarize the case and suggest next steps.

The attached context includes the following case details:

  • Case ID
  • Title
  • Description
  • Status
  • Severity
  • Tags
  • Assignees
  • Category
  • Created and updated timestamps
  • Alert, comment, attachment, and observable counts
  • Connector name
  • A link back to the case

After a case is attached, you can ask the agent to act on it directly from the conversation. For example, you can:

  • Add case comments. For example, after the agent summarizes a case, you can ask it to add that summary as a comment.
  • Update case metadata, such as the status, severity, tags, category, title, and description.
  • Change the assignees.
  • Add attachments, such as alerts, events, or observables.

If you keep the chat open, the case page updates in real time to show any changes the agent makes.

The case's activity feed also records each change the agent makes, with via and the agent name after the username. Refer to See how an action started.