View as Markdown
Elastic Security icon

Elastic Security ACTION

Add Case Comment

Add a user comment to an Elastic Security case via POST /api/cases/{caseId}/comments. Use this to log investigation notes or updates on a case without changing its status or fields — use Create or Update Case for that. Run Find Cases first to obtain a valid case ID. Example: calling with caseId: "a1c1..." and comment: "Confirmed unauthorized access via badge logs." returns the updated case object with totalComment incremented and the new comment in comments. See the documentation
  • Action
  • Writes data
  • API key
  • SDK
  • MCP

IMPLEMENTATION

Call this tool

Connect a user's Elastic Security account once, then configure and run Add Case Comment from your backend or agent.

import { PipedreamClient } from "@pipedream/sdk"

const pd = new PipedreamClient({
  projectId: process.env.PIPEDREAM_PROJECT_ID!,
  clientId: process.env.PIPEDREAM_CLIENT_ID!,
  clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
  projectEnvironment: "production",
})

const result = await pd.actions.run({
  id: "elastic_security-add-case-comment",
  externalUserId: "{external_user_id}", // any stable ID for this user in your system
  configuredProps: {
    elastic_security: { authProvisionId: "apn_xxxxxxx" },
    caseId: "Case ID",
    comment: "Comment",
  },
})

console.log(result)

SCHEMA

Inputs

Pipedream supplies the connected account. Your application provides the operation-specific values below. Dynamic inputs are resolved against that user's account.

Add Case Comment inputs
Property Type Description
caseId Case ID string
The ID of the case to comment on. Run Find Cases first to obtain valid case IDs.
Required
comment Comment string
The text of the user comment to add.
Required

REFERENCE

Tool details

Behavior hints are published with the component in the Pipedream registry and surface as MCP tool annotations, so an agent can reason about a tool before it calls it.

Registry key
elastic_security-add-case-comment
Version
0.0.1
App
Elastic Security
Authentication
API key
Read-only
No
Destructive
No
Open world
Yes