I personally don't feel like it would be a popular request.
I personally feel like I could really use this kind of functionality. The SIEM signals data is not exposed except to some security / soc personel. When we need to escalate this to application teams / management or others, they ask for details. A quick export to csv of only the selected signals and email / attach to a ticket to who needs it is the use case. This so they can know what's it about without needing access to the SIEM signals index and related datasets.
Maybe the reason I need this is because I have absolutely no use at all from the way the Kibana Case Incident Management System works currently. As I already tried to explain in Case Connectors the limited amount of supported ITSM connectors and the fact that we cannot use a webhook might lead to me needing other ways to share relevant signals and info to stakeholders.
Allowing a quick export to csv of only the selected signals would imho be much quicker and easier then having to drag the signals to a timeline, then create a case from the timeline, then find some way to create an ITSM ticket which has the same data as in the Kibana case.
Export to csv should take like 3 sec and attach this csv to an itsm ticket could take another 10s which together is a lot shorter then what I got to do now. Exporting to csv would also allow to import in excel or sth similar and further aggregate / analyse there. (Some people (like mgmt) will never use a tool like Kibana, but Excel comes natural for them)