> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tracecat.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Linked rows

> Link table rows to a case to keep structured evidence such as indicators, assets, and detections with the investigation.

Link table rows to a case to connect it to structured data.
Use them when a case needs more than free-form notes, such as indicators, assets, or external detections.

<img src="https://mintcdn.com/tracecat/O3EeW3V5Iek0f9qX/img/cases/linked-rows.png?fit=max&auto=format&n=O3EeW3V5Iek0f9qX&q=85&s=30716d42c7a43765e8841d545e8a4a27" alt="Linked rows" width="790" height="330" data-path="img/cases/linked-rows.png" />

Each linked table renders as its own grid in the case's Tables tab, 20 rows at a time; page with the arrows in the table header. To link rows from the case page:

<Steps>
  <Step title="Open the Tables tab">
    Open the case and select the Tables tab.
  </Step>

  <Step title="Pick a table and rows">
    Click `Link table`, choose a table, and tick the rows to link.
    Your selection is kept while you page through the table or switch to another table, so you can pick rows from several tables at once.
  </Step>

  <Step title="Add the rows">
    Click `Add rows`. Tracecat skips rows that are already linked to the case.
  </Step>
</Steps>

<img src="https://mintcdn.com/tracecat/vdJgDv881hJyN9D4/img/cases/link-rows-dialog.png?fit=max&auto=format&n=vdJgDv881hJyN9D4&q=85&s=d6a6cd5d7bea82bf2fcf1e87c579e39f" alt="Link rows dialog" width="3200" height="2000" data-path="img/cases/link-rows-dialog.png" />

To link more rows from a table that is already linked, click `Link rows` in that table's header.
Click `Add row` to create a new row in the table and link it to the case.
Right-click a row to edit it, unlink it, or [view related cases](/automations/cases/correlations).
To unlink several rows at once, tick them in the grid and click `Unlink`.

A case can link up to 250 rows from each table and rows from up to 10 tables. Each link or unlink request takes at most 100 row IDs.

For example, you can link:

* Related SIEM alerts
* Indicators of compromise (IoCs)
* Affected assets such as hosts, users, or devices
* Threat intelligence matches
* Evidence artifacts such as domains, IPs, or hashes

Linked rows are especially useful when workflows enrich a case over time.
You can insert new rows as evidence arrives or link existing rows that are already part of another workflow or lookup table.

Linked rows use regular tables.
When you create a table for case-linked evidence, use the same `columns` JSON schema documented in [Tables](/automations/tables) and [Table actions](/automations/core-actions/memory-actions/tables).

## Related pages

* See [Correlations](/automations/cases/correlations) to find other cases that link the same row.
* See [Case management](/automations/cases) for an overview of case features.
* See [Linked rows](/automations/core-actions/case-actions/linked-rows) to link table rows to a case from a workflow.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.