Skip to content

[Internal]: Document new advanced setting for max cases per rule run (Cases alert action) #5867

Open
nastasha-solomon wants to merge 4 commits intomainfrom
issue-5737-sec
Open

[Internal]: Document new advanced setting for max cases per rule run (Cases alert action) #5867
nastasha-solomon wants to merge 4 commits intomainfrom
issue-5737-sec

Conversation

@nastasha-solomon
Copy link
Copy Markdown
Member

@nastasha-solomon nastasha-solomon commented Apr 11, 2026

Summary

⚠️ Don't merge this doc PR until after elastic/kibana#264070 is merged ⚠️

Fixes #5737 by adding a section for the new maxOpenCasesPerRuleRun advanced setting. The section covers the following:

  • What the setting controls (the maximum cases created per rule run)
  • The default value (20) and allowed range (1–1000)
  • Practical guidance for high-volume environments
  • A note that Attack Discovery keeps its own case-creation limit and is unaffected

Corresponding Kibana PR: elastic/kibana#263876

Generative AI disclosure

  1. Did you use a generative AI (GenAI) tool to assist in creating this contribution?
  • Yes
  • No

Cursor + Composer

@nastasha-solomon nastasha-solomon self-assigned this Apr 11, 2026
@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented Apr 11, 2026

🔍 Preview links for changed docs

@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented Apr 11, 2026

✅ Vale Linting Results

No issues found on modified lines!


The Vale linter checks documentation changes against the Elastic Docs style guide.

To use Vale locally or report issues, refer to Elastic style guide for Vale.

Copy link
Copy Markdown

@janmonschke janmonschke left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Docs lgtm!

@janmonschke
Copy link
Copy Markdown

@nastasha-solomon The serverless config PR has been merged

@nastasha-solomon
Copy link
Copy Markdown
Member Author

Still promoting to prod non canary. Will check back EOD and merge this PR if this advanced setting is available in the UI.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Internal]: Document new advanced setting for max cases per rule run (Cases alert action)

2 participants