CYBERSECURITYTRACKER
TRACKING6,902 stories in this site build1,444 vulnerability news stories in this site build
Permanent story citation

SOC case management and detection rule history in Elastic Security

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3759

As cited

Copy frozen at (site build).

cloud saas

SOC case management and detection rule history in Elastic Security

Elastic Security 9.5 introduces detection rule change history with point-in-time comparisons and one-click rollback, creating an immutable audit trail for compliance. Case management gains customizable templates with new field types and enforcement options, while case analytics now ship enabled by default across three global indices instead of requiring manual configuration per space. These features enable SOC teams to track investigation data consistently and debug rule changes without external tooling.

Why it matters: Security operations and compliance teams need reliable audit trails for detection rule changes and investigation case data to meet standards like SOC 2, ISO 27001, and DORA; these GA features eliminate manual configuration work and provide out-of-box dashboarding on case metrics and rule history.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary