Skip to main content
Link table rows to a case to connect it to structured data. Use them when a case needs more than free-form notes, such as indicators, assets, or external detections. Linked rows Each linked table renders as its own grid in the case’s Tables tab, 20 rows at a time; page with the arrows in the table header. To link rows from the case page:
1

Open the Tables tab

Open the case and select the Tables tab.
2

Pick a table and rows

Click Link table, choose a table, and tick the rows to link. Your selection is kept while you page through the table or switch to another table, so you can pick rows from several tables at once.
3

Add the rows

Click Add rows. Tracecat skips rows that are already linked to the case.
Link rows dialog To link more rows from a table that is already linked, click Link rows in that table’s header. Click Add row to create a new row in the table and link it to the case. Right-click a row to edit it, unlink it, or view related cases. To unlink several rows at once, tick them in the grid and click Unlink. A case can link up to 250 rows from each table and rows from up to 10 tables. Each link or unlink request takes at most 100 row IDs. For example, you can link:
  • Related SIEM alerts
  • Indicators of compromise (IoCs)
  • Affected assets such as hosts, users, or devices
  • Threat intelligence matches
  • Evidence artifacts such as domains, IPs, or hashes
Linked rows are especially useful when workflows enrich a case over time. You can insert new rows as evidence arrives or link existing rows that are already part of another workflow or lookup table. Linked rows use regular tables. When you create a table for case-linked evidence, use the same columns JSON schema documented in Tables and Table actions.