Skip to main content
Enterprise Edition

Correlations

Correlations show every other case that links the same table row. Use them to spot campaigns, repeat offenders, and shared infrastructure: if two cases link the same IP address row, the cases are related. View related cases Correlations build on linked rows. Tracecat matches rows by row ID, so link the existing row instead of inserting a duplicate when the same indicator appears in a new case.
1

Open the Tables tab

Open the case and select the Tables tab.
2

Right-click a row

Right-click a linked row and select View related cases.
3

Review the cases

The Related cases drawer shows the row’s data and every other case that links it. The current case is left out.
Row menu Each related case shows its short ID, summary, priority, severity, tags, and when it was created and updated. Hover a case to preview its status, assignee, tasks, dropdowns, and custom fields. Click a case to keep its preview open. Click Open case, or Ctrl-click or Cmd-click the case, to open it in a new tab. If more cases link the row, click Load more at the bottom of the list. Related cases drawer

Correlate cases in workflows

Use core.cases.list_cases_by_row to find cases that link a row. Pass exclude_case_id to leave out the current case.
Combine it with a case trigger on table_row_linked to comment on or escalate a case as soon as an analyst or workflow links a row that already appears in other cases.