Elastic Kibana V9
elastic kibana v9 is a data visualization and exploration tool that enables users to interact with data stored in elasticsearch elastic kibana v9 is a powerful data visualization and exploration tool that allows users to analyze and visualize data in real time the elastic kibana v9 connector for swimlane turbine enables seamless integration with kibana's case management and alert handling capabilities this integration empowers security teams to automate the creation, management, and updating of cases and alerts, enhancing incident response efficiency by leveraging kibana's robust features, swimlane turbine users can streamline their security operations, reduce manual efforts, and improve overall security posture limitations none to date supported versions this elastic kibana v9 connector uses the version 9 api additional documents documentation elastic kibana v9 https //www elastic co/docs/api/doc/kibana/v9/authentication prerequisites before you can use the elastic kibana v9 connector for turbine, you'll need access to the elastic kibana api this requires the following http basic authentication using the following parameters url the endpoint for your elastic kibana instance username your elastic kibana username password your elastic kibana password api key authentication using the following parameters url the endpoint for your elastic kibana instance api key a valid api key for accessing elastic kibana authentication methods api key authentication method url the endpoint for accessing the elastic kibana api api key a unique key provided by elastic for authenticating api requests http basic authentication method url the endpoint for accessing the elastic kibana api username your elastic kibana account username password the password associated with your elastic kibana account capabilities this connector provides the following capabilities add a case comment or alert attach a file to a case create a case create a conversation create a model response create a rule delete cases delete a case comment or alert delete a conversation delete a rule disable a rule enable a rule get all alerts for a case get conversations get information about rules and so on add a case comment or alert add a comment or alert to a case in elastic kibana v9 using the specified caseid as a path parameter and provide additional details in the json body click here https //www elastic co/docs/api/doc/kibana/v9/operation/operation addcasecommentdefaultspace attach a file to a case attach a file to a case in elastic kibana v9 using the caseid and file details provided in the json body click here https //www elastic co/docs/api/doc/kibana/v9/operation/operation addcasefiledefaultspace create a case create a case in elastic kibana v9 with specified connector, description, owner, settings, tags, and title click here https //www elastic co/docs/api/doc/kibana/v9/operation/operation createcasedefaultspace create a conversation initiate a new conversation in elastic kibana v9 using the provided title in the json body click here https //www elastic co/docs/api/doc/kibana/v9/operation/operation createconversation create a model response create a model response in elastic kibana v9 using connectorid, persist, and messages this action requires json body and content references disabled parameters click here https //www elastic co/docs/api/doc/kibana/v9/operation/operation chatcomplete create a rule create a rule in elastic kibana v9 using specified json body and path parameters, including the rule id click here https //www elastic co/docs/api/doc/kibana/v9/operation/operation post alerting rule id delete cases delete cases in elastic kibana v9 to manage and organize your case data efficiently click here https //www elastic co/docs/api/doc/kibana/v9/operation/operation deletecasedefaultspace delete a case comment or alert delete a case comment or alert in elastic kibana v9 using the specified caseid and commentid as path parameters click here https //www elastic co/docs/api/doc/kibana/v9/operation/operation deletecasecommentdefaultspace delete a conversation permanently delete an existing conversation in elastic kibana v9 using the conversation id as a path parameter click here https //www elastic co/docs/api/doc/kibana/v9/operation/operation deleteconversation delete a rule delete a rule in elastic kibana v9 using the specified rule id as a path parameter click here https //www elastic co/docs/api/doc/kibana/v9/operation/operation delete alerting rule id disable a rule disable a rule in elastic kibana v9 using the rule id and untrack status click here https //www elastic co/docs/api/doc/kibana/v9/operation/operation post alerting rule id disable enable a rule enable a specific rule in elastic kibana v9 using the rule id as a path parameter click here https //www elastic co/docs/api/doc/kibana/v9/operation/operation post alerting rule id enable get all alerts for a case get all alerts associated with a specific case in elastic kibana v9 click here https //www elastic co/docs/api/doc/kibana/v9/operation/operation getcasealertsdefaultspace get conversations fetch and display conversations from elastic kibana v9 for analysis and review click here https //www elastic co/docs/api/doc/kibana/v9/operation/operation findconversations get information about rules get information about rules click here https //www elastic co/docs/api/doc/kibana/v9/operation/operation get alerting rules find get a conversation retrieve details of an existing conversation in elastic kibana v9 using the unique conversation id click here https //www elastic co/docs/api/doc/kibana/v9/operation/operation readconversation search cases search for cases in elastic kibana v9 and retrieve relevant information click here https //www elastic co/docs/api/doc/kibana/v9/operation/operation findcasesdefaultspace update cases update existing cases in elastic kibana v9 using the provided json body containing case details click here https //www elastic co/docs/api/doc/kibana/v9/operation/operation updatecasedefaultspace update a case comment or alert update a case comment or alert in elastic kibana v9 using the specified caseid and json body click here https //www elastic co/docs/api/doc/kibana/v9/operation/operation updatecasecommentdefaultspace update a conversation update a conversation in elastic kibana v9 using the title and id as inputs click here https //www elastic co/docs/api/doc/kibana/v9/operation/operation updateconversation update a rule update a specific rule in elastic kibana v9 using the rule id, schedule, and name click here https //www elastic co/docs/api/doc/kibana/v9/operation/operation put alerting rule id configurations elastick kibana v9 api key authentication authenticates using an api key configuration parameters parameter description type required url a url to the target host string required port host port to use number optional space the kibana space id to target defaults to the 'default' space if not provided string optional x apikey api key string required verify ssl verify ssl certificate boolean optional http proxy a proxy to route requests through string optional elastick kibana v9 http basic authentication authenticates using username and password configuration parameters parameter description type required url a url to the target host string required port host port to use number optional space the kibana space id to target defaults to the 'default' space if not provided string optional username username string required password password string required verify ssl verify ssl certificate boolean optional http proxy a proxy to route requests through string optional actions add a case comment or alert add a comment or alert to a case in elastic kibana v9 using the specified caseid as a path parameter and provide additional details in the json body endpoint url /api/cases/{{caseid}}/comments method post input argument name type required description path parameters caseid string required the id of the case to add a comment or alert to alertid array optional the id of the alert to add to the case index array optional the index of the alert to add to the case owner string optional the application that owns the cases stack management, observability, or elastic security rule object optional the rule of the alert to add to the case rule id string optional unique identifier rule name string optional name of the resource type string optional the type of the comment or alert to add to the case comment string optional the comment to add to the case input example {"json body" {"alertid" \["8af6ac20 74f6 11ea b83a 553aecdb28b6"],"index" \["8af6ac20 74f6 11ea b83a 553aecdb28b6"],"owner" "cases","rule" {"id" "8af6ac20 74f6 11ea b83a 553aecdb28b6","name" "rule 1"},"type" "alert","comment" "this is a comment"},"path parameters" {"caseid" "8af6ac20 74f6 11ea b83a 553aecdb28b6"}} output parameter type description status code number http status code of the response reason string response reason phrase assignees array output field assignees category object output field category closed at object output field closed at closed by object output field closed by comments array output field comments comments comment string output field comments comment comments created at string output field comments created at comments created by object output field comments created by comments created by email object output field comments created by email comments created by full name object name of the resource comments created by profile uid string unique identifier comments created by username string name of the resource comments id string unique identifier comments owner string output field comments owner comments pushed at object output field comments pushed at comments pushed by object output field comments pushed by comments type string type of the resource comments updated at object output field comments updated at comments updated by object output field comments updated by comments version string output field comments version connector object output field connector connector fields object output field connector fields connector id string unique identifier output example {"status code" 200,"response headers" {},"reason" "ok","json body" {"assignees" \[],"category"\ null,"closed at"\ null,"closed by"\ null,"comments" \[{}],"connector" {"fields"\ null,"id" "none","name" "none","type" " none"},"created at" "2022 03 24t00 37 03 906z","created by" {"email"\ null,"full name"\ null,"profile uid" "u mgbrof q5bmfcatblxaccwka0k8jvonawsruelyka5e 0","username" "elastic"},"customfields" \[{},{}],"description" "a case description ","duration"\ null,"external service"\ null,"id" "293f1bc attach a file to a case attach a file to a case in elastic kibana v9 using the specified caseid and file details provided in the json body endpoint url /api/cases/{{caseid}}/files method post input argument name type required description path parameters caseid string required the id of the case to attach a file to file object optional parameter for attach a file to a case file file name string optional name of the resource file file string optional parameter for attach a file to a case input example {"json body" {"file" {"file name" "test txt","file" "vghpcybpcybhihrlc3qgzmlszs4="}},"path parameters" {"caseid" "9c235210 6834 11ea a78c 6ffb38a34414"}} output parameter type description status code number http status code of the response reason string response reason phrase assignees array output field assignees category object output field category closed at object output field closed at closed by object output field closed by comments array output field comments comments comment string output field comments comment comments created at string output field comments created at comments created by object output field comments created by comments created by email object output field comments created by email comments created by full name object name of the resource comments created by profile uid string unique identifier comments created by username string name of the resource comments id string unique identifier comments owner string output field comments owner comments pushed at object output field comments pushed at comments pushed by object output field comments pushed by comments type string type of the resource comments updated at object output field comments updated at comments updated by object output field comments updated by comments version string output field comments version connector object output field connector connector fields object output field connector fields connector id string unique identifier output example {"status code" 200,"response headers" {},"reason" "ok","json body" {"assignees" \[],"category"\ null,"closed at"\ null,"closed by"\ null,"comments" \[{}],"connector" {"fields"\ null,"id" "none","name" "none","type" " none"},"created at" "2022 03 24t00 37 03 906z","created by" {"email"\ null,"full name"\ null,"profile uid" "u mgbrof q5bmfcatblxaccwka0k8jvonawsruelyka5e 0","username" "elastic"},"customfields" \[{},{}],"description" "a case description ","duration"\ null,"external service"\ null,"id" "293f1bc create a case create a case in elastic kibana v9 using specified connector, description, owner, settings, tags, and title endpoint url /api/cases method post input argument name type required description assignee array optional an array containing users that are assigned to the case category string optional a word or phrase that categorizes the case connector object optional defines properties for connectors when type is none customfields array optional custom field values for a case any optional custom fields that are not specified in the request are set to null description string optional the description for the case owner string optional the application that owns the cases stack management, observability, or elastic security settings object optional an object that contains the case settings severity string optional the severity of the case tags array optional the words and phrases that help categorize cases it can be an empty array title string optional a title for the case input example {"json body" {"assignee" \[{}],"category" "cases","connector" {},"customfields" \[{}],"description" "a case description ","owner" "cases","settings" {},"severity" "high","tags" \["tag 1"],"title" "case title 1"}} output parameter type description status code number http status code of the response reason string response reason phrase assignees array output field assignees closed at object output field closed at closed by object output field closed by comments array output field comments connector object output field connector connector fields object output field connector fields connector fields issuetype string type of the resource connector fields parent object output field connector fields parent connector fields priority string output field connector fields priority connector id string unique identifier connector name string name of the resource connector type string type of the resource created at string output field created at created by object output field created by created by email object output field created by email created by full name object name of the resource created by profile uid string unique identifier created by username string name of the resource customfields array output field customfields customfields key string output field customfields key customfields type string type of the resource customfields value object value for the parameter description string output field description output example {"status code" 200,"response headers" {},"reason" "ok","json body" {"assignees" \[],"closed at"\ null,"closed by"\ null,"comments" \[],"connector" {"fields" {},"id" "131d4448 abe0 4789 939d 8ef60680b498","name" "my connector","type" " jira"},"created at" "2022 10 13t15 33 50 604z","created by" {"email"\ null,"full name"\ null,"profile uid" "u mgbrof q5bmfcatblxaccwka0k8jvonawsruelyka5e 0","username" "elastic"},"customfields" \[{},{}],"description" "a case description ","duration"\ null,"external service create a conversation initiate a new conversation in elastic kibana v9 using the provided title in the json body endpoint url /api/security ai assistant/current user/conversations method post input argument name type required description apiconfig object optional parameter for create a conversation apiconfig actiontypeid string optional the id of the action type apiconfig connectorid string optional the id of the connector apiconfig defaultsystempromptid string optional the id of the default system prompt apiconfig model string optional the model to use for the conversation apiconfig provider string optional the provider to use for the conversation category string optional the category of the conversation excludefromlastconversationstorage boolean optional whether to exclude the conversation from the last conversation storage id string optional the id of the conversation messages array optional response message messages content string optional the content of the message messages role string optional the role of the message messages timestamp string optional the timestamp of the message replacements object optional the replacements for the conversation title string optional the title of the conversation input example {"json body" {"apiconfig" {"actiontypeid" "67890","connectorid" "12345","defaultsystempromptid" "12345","model" "gpt 4o mini","provider" "openai"},"category" "assistant","excludefromlastconversationstorage"\ false,"id" "12345","messages" \[{"content" "hello, how can i assist you today?","role" "system","timestamp" "2023 10 31t12 00 00z"}],"replacements" {},"title" "security discussion"}} output parameter type description status code number http status code of the response reason string response reason phrase apiconfig object output field apiconfig apiconfig actiontypeid string unique identifier apiconfig connectorid string unique identifier category string output field category createdat string output field createdat excludefromlastconversationstorage boolean output field excludefromlastconversationstorage id string unique identifier messages array response message messages content string response content messages role string response message messages timestamp string response message replacements object output field replacements title string output field title updatedat string output field updatedat users array output field users users id string unique identifier users name string name of the resource output example {"status code" 200,"response headers" {},"reason" "ok","json body" {"apiconfig" {"actiontypeid" "67890","connectorid" "12345"},"category" "assistant","createdat" "2023 10 31t12 01 00z","excludefromlastconversationstorage"\ false,"id" "abc123","messages" \[{}],"replacements" {},"title" "security discussion","updatedat" "2023 10 31t12 01 00z","users" \[{}]}} create a model response create a model response in elastic kibana v9 using connectorid, persist, and messages requires json body and content references disabled parameters endpoint url /api/security ai assistant/chat/complete method post input argument name type required description parameters content references disabled boolean required whether to disable content references connectorid string optional the id of the connector conversationid string optional the id of the conversation isstream boolean optional whether to stream the response langsmithapikey string optional the api key for the langsmith project langsmithproject string optional the project for the langsmith api key messages array optional response message messages content string optional the content of the message messages data object optional the data of the message messages data user id string optional the id of the user messages fields to anonymize array optional the fields to anonymize messages role string optional the role of the message model string optional the model to use for the response persist boolean optional whether to persist the response promptid string optional the id of the prompt responselanguage string optional the language of the response input example {"parameters" {"content references disabled"\ false},"json body" {"connectorid" "conn 001","conversationid" "abc123","isstream"\ true,"langsmithapikey" "sk abc123","langsmithproject" "security ai project","messages" \[{"content" "what are some common phishing techniques?","data" {"user id" "user 789"},"fields to anonymize" \["user name","source ip"],"role" "user"}],"model" "gpt 4","persist"\ true,"promptid" "prompt 456","responselanguage" "en"}} output parameter type description status code number http status code of the response reason string response reason phrase output example {"status code" 200,"response headers" {},"reason" "ok","json body" {}} create a rule create a rule in elastic kibana v9 using specified json body and path parameters, including the rule id endpoint url /api/alerting/rule/{{id}} method post input argument name type required description path parameters id string required the id of the rule actions array optional the actions to perform when the rule is triggered alert delay object optional the delay before the alert is triggered artifacts object optional the artifacts to attach to the alert enabled boolean optional whether the rule is enabled consumer string optional the consumer of the rule name string optional the name of the rule params object optional the parameters of the rule rule type id string optional the type of the rule schedule object optional the schedule of the rule schedule interval string optional the interval of the schedule input example {"json body" {"actions" \[{}],"alert delay" {},"artifacts" {},"enabled"\ true,"consumer" "stackalerts","name" "my elasticsearch query esql rule","params" {},"rule type id" " es query","schedule" {"interval" "1d"}},"path parameters" {"id" "d0db1fe0 78d6 11ee 9177 f7d404c8c945"}} output parameter type description status code number http status code of the response reason string response reason phrase actions array output field actions actions connector type id string unique identifier actions frequency object output field actions frequency actions frequency notify when string output field actions frequency notify when actions frequency summary boolean output field actions frequency summary actions frequency throttle object output field actions frequency throttle actions group string output field actions group actions id string unique identifier actions params object output field actions params actions params level string output field actions params level actions params message string response message actions uuid string unique identifier api key created by user boolean output field api key created by user api key owner string output field api key owner consumer string output field consumer created at string output field created at created by string output field created by enabled boolean output field enabled execution status object status value execution status last execution date string status value execution status status string status value id string unique identifier mute all boolean output field mute all output example {"status code" 200,"response headers" {},"reason" "ok","json body" {"actions" \[{}],"api key created by user"\ false,"api key owner" "elastic","consumer" "stackalerts","created at" "2023 11 01t19 00 10 453z","created by" "elastic","enabled"\ true,"execution status" {"last execution date" "2023 11 01t19 00 10 453z","status" "pending"},"id" "e0d62360 78e8 11ee 9177 f7d404c8c945","mute all"\ false,"muted alert ids" \[],"name" "my elasticsearch query esql rule","notify when"\ null,"params" {"aggtype" "cou delete a case comment or alert delete a case comment or alert in elastic kibana v9 using the specified caseid and commentid as path parameters endpoint url /api/cases/{{caseid}}/comments/{{commentid}} method delete input argument name type required description path parameters caseid string required the id of the case to delete a comment or alert from path parameters commentid string required the id of the comment to delete from the case input example {"path parameters" {"caseid" "8af6ac20 74f6 11ea b83a 553aecdb28b6","commentid" "8af6ac20 74f6 11ea b83a 553aecdb28b6"}} output parameter type description status code number http status code of the response reason string response reason phrase response text string output field response text output example {"status code" 204,"response headers" {},"reason" "no content","response text" ""} delete a conversation permanently delete an existing conversation in elastic kibana v9 using the conversation id as a path parameter endpoint url /api/security ai assistant/current user/conversations/{{id}} method delete input argument name type required description path parameters id string required parameters for the delete a conversation action input example {"path parameters" {"id" "12345"}} output parameter type description status code number http status code of the response reason string response reason phrase apiconfig object output field apiconfig apiconfig actiontypeid string unique identifier apiconfig connectorid string unique identifier category string output field category createdat string output field createdat excludefromlastconversationstorage boolean output field excludefromlastconversationstorage id string unique identifier messages array response message messages content string response content messages role string response message messages timestamp string response message replacements object output field replacements title string output field title updatedat string output field updatedat users array output field users users id string unique identifier users name string name of the resource output example {"status code" 200,"response headers" {},"reason" "ok","json body" {"apiconfig" {"actiontypeid" "67890","connectorid" "12345"},"category" "assistant","createdat" "2023 10 31t12 01 00z","excludefromlastconversationstorage"\ false,"id" "abc123","messages" \[{}],"replacements" {},"title" "deleted security discussion","updatedat" "2023 10 31t12 01 00z","users" \[{}]}} delete a rule delete a rule in elastic kibana v9 using the specified rule id as a path parameter endpoint url /api/alerting/rule/{{id}} method delete input argument name type required description path parameters id string required parameters for the delete a rule action input example {"path parameters" {"id" "96b668d0 a1b6 11ed afdf d39a49596974"}} output parameter type description status code number http status code of the response reason string response reason phrase response text string output field response text output example {"status code" 204,"response headers" {},"reason" "no content","response text" ""} delete cases delete cases in elastic kibana v9 to manage and organize your case data efficiently endpoint url /api/cases method delete input argument name type required description parameters ids array optional parameters for the delete cases action input example {"parameters" {"ids" \["131d4448 abe0 4789 939d 8ef60680b498"]}} output parameter type description status code number http status code of the response reason string response reason phrase response text string output field response text output example {"status code" 204,"response headers" {},"reason" "no content","response text" ""} disable a rule disable a rule in elastic kibana v9 using the rule id and untrack status requires path parameters and json body endpoint url /api/alerting/rule/{{id}}/ disable method post input argument name type required description path parameters id string required the identifier for the rule untrack boolean optional defines whether this rule's alerts should be untracked input example {"json body" {"untrack"\ true},"path parameters" {"id" "96b668d0 a1b6 11ed afdf d39a49596974"}} output parameter type description status code number http status code of the response reason string response reason phrase response text string output field response text output example {"status code" 204,"response headers" {},"reason" "no content","response text" ""} enable a rule enable a specific rule in elastic kibana v9 using the rule id as a path parameter endpoint url /api/alerting/rule/{{id}}/ enable method post input argument name type required description path parameters id string required the identifier for the rule input example {"path parameters" {"id" "96b668d0 a1b6 11ed afdf d39a49596974"}} output parameter type description status code number http status code of the response reason string response reason phrase response text string output field response text output example {"status code" 204,"response headers" {},"reason" "no content","response text" ""} get a conversation retrieve details of an existing conversation in elastic kibana v9 using the unique conversation id endpoint url /api/security ai assistant/current user/conversations/{{id}} method get input argument name type required description path parameters id string required the id of the conversation to get input example {"path parameters" {"id" "12345"}} output parameter type description status code number http status code of the response reason string response reason phrase apiconfig object output field apiconfig apiconfig actiontypeid string unique identifier apiconfig connectorid string unique identifier category string output field category createdat string output field createdat excludefromlastconversationstorage boolean output field excludefromlastconversationstorage id string unique identifier messages array response message messages content string response content messages role string response message messages timestamp string response message replacements object output field replacements title string output field title updatedat string output field updatedat users array output field users users id string unique identifier users name string name of the resource output example {"status code" 200,"response headers" {},"reason" "ok","json body" {"apiconfig" {"actiontypeid" "67890","connectorid" "12345"},"category" "assistant","createdat" "2023 10 31t12 01 00z","excludefromlastconversationstorage"\ false,"id" "abc123","messages" \[{}],"replacements" {},"title" "security discussion","updatedat" "2023 10 31t12 01 00z","users" \[{}]}} get all alerts for a case get all alerts associated with a specific case in elastic kibana v9 using the caseid path parameter endpoint url /api/cases/{{caseid}}/alerts method get input argument name type required description path parameters caseid string required parameters for the get all alerts for a case action input example {"path parameters" {"caseid" "f6a7d0c3 d52d 432c b2e6 447cd7fce04d"}} output parameter type description status code number http status code of the response reason string response reason phrase output example {"status code" 200,"response headers" {},"reason" "ok","json body" \[{"attached at" "2022 07 25t20 09 40 963z","id" "f6a7d0c3 d52d 432c b2e6 447cd7fce04d","index" " alerts observability logs alerts default"}]} get conversations fetch and display conversations from elastic kibana v9 for analysis and review endpoint url /api/security ai assistant/current user/conversations/ find method get input argument name type required description parameters fields string optional a list of fields to include in the response if omitted, all fields are returned parameters filter string optional a search query to filter the conversations can match against titles, messages, or other conversation attributes parameters sort field string optional the field by which to sort the results valid fields are created at, title, and updated at parameters sort order string optional the order in which to sort the results can be either asc for ascending or desc for descending parameters page number optional the page number of the results to retrieve parameters page size number optional the number of conversations to return per page parameters is owner boolean optional whether to return conversations that the current user owns if true, only conversations owned by the user are returned input example {"parameters" {"fields" "title","filter" "title\ security discussion","sort field" "title","sort order" "asc","page" 1,"page size" 10,"is owner"\ true}} output parameter type description status code number http status code of the response reason string response reason phrase output example {"status code" 200,"response headers" {},"reason" "ok","json body" {}} get information about rules get detailed information about rules in elastic kibana v9, including their configurations and statuses endpoint url /api/alerting/rules/ find method get input argument name type required description parameters per page number optional the number of rules to return per page parameters page number optional the page number to return parameters search string optional an elasticsearch simple query string query that filters the objects in the response parameters default search operator string optional the default operator to use for the simple query string parameters search fields string optional the fields to perform the simple query string parsed query against parameters sort field string optional determines which field is used to sort the results the field must exist in the attributes key of the response parameters sort order string optional determines the sort order parameters fields string optional the fields to return in the attributes key of the response parameters filter string optional a kql string that you filter with an attribute from your saved object it should look like savedobjecttype updatedat > 2018 12 22 parameters filter consumers string optional list of consumers to filter input example {"parameters" {"per page" 10,"page" 1,"search" "test","default search operator" "and","search fields" "name,description","sort field" "name","sort order" "asc","fields" "name,description","filter" "name\ test","filter consumers" "test"}} output parameter type description status code number http status code of the response reason string response reason phrase data array response data data actions array response data data actions frequency object response data data actions frequency notify when string response data data actions frequency summary boolean response data data actions frequency throttle object response data data actions group string response data data actions id string response data data actions params object response data data actions params connector type id string response data data actions params level string response data data actions params message string response data data actions uuid string response data data api key created by user boolean response data data api key owner string response data data consumer string response data data created at string response data data created by string response data data enabled boolean response data data execution status object response data data execution status last duration number response data data execution status last execution date string response data data execution status status string response data output example {"status code" 200,"response headers" {},"reason" "ok","json body" {"data" \[{}],"page" 1,"per page" 10,"total" 1}} search cases search for cases in elastic kibana v9 and retrieve relevant information endpoint url /api/cases/ find method get input argument name type required description parameters assignees string optional filters the returned cases by assignees valid values are none or unique identifiers for the user profiles these identifiers can be found by using the suggest user profile api parameters category string optional filters the returned cases by category parameters defaultsearchoperator string optional he default operator to use for the simple query string parameters from string optional returns only cases that were created after a specific date the date must be specified as a kql data range or date match expression parameters owner string optional a filter to limit the response to a specific set of applications if this parameter is omitted, the response contains information about all the cases that the user has access to read parameters page number optional the page number to return parameters perpage number optional the number of cases to return per page maximum is 100 parameters reporters array optional filters the returned cases by the user name of the reporter parameters search string optional an elasticsearch simple query string query that filters the objects in the response parameters searchfields array optional the fields to perform the simple query string parsed query against parameters severity string optional the severity of the case parameters sortfield string optional the field to sort the results by parameters sortorder string optional the order to sort the results by parameters status string optional tfilters the returned cases by state parameters tags array optional filters the returned cases by tags parameters to string optional returns only cases that were created before a specific date the date must be specified as a kql data range or date match expression input example {"parameters" {"assignees" "u mgbrof q5bmfcatblxaccwka0k8jvonawsruelyka5e 0","category" "cases","defaultsearchoperator" "or","from" "now 7d","owner" "cases","page" 1,"perpage" 20,"reporters" \["elastic"],"search" "case title 1","searchfields" \["title"],"severity" "high","sortfield" "createdat","sortorder" "desc","status" "open","tags" \["tag 1"],"to" "now"}} output parameter type description status code number http status code of the response reason string response reason phrase cases array output field cases cases assignees array output field cases assignees cases category object output field cases category cases closed at object output field cases closed at cases closed by object output field cases closed by cases comments array output field cases comments cases connector object output field cases connector cases connector fields object output field cases connector fields cases connector id string unique identifier cases connector name string name of the resource cases connector type string type of the resource cases created at string output field cases created at cases created by object output field cases created by cases created by email object output field cases created by email cases created by full name object name of the resource cases created by profile uid string unique identifier cases created by username string name of the resource cases customfields array output field cases customfields cases customfields key string output field cases customfields key cases customfields type string type of the resource cases customfields value object value for the parameter cases description string output field cases description cases duration object output field cases duration output example {"status code" 200,"response headers" {},"reason" "ok","json body" {"cases" \[{}],"count closed cases" 0,"count in progress cases" 0,"count open cases" 1,"page" 1,"per page" 5,"total" 1}} update a case comment or alert update a case comment or alert in elastic kibana v9 using the specified caseid and json body endpoint url /api/cases/{{caseid}}/comments method patch input argument name type required description path parameters caseid string required the id of the case to add a comment or alert to alertid array optional the id of the alert to add to the case index array optional the index of the alert to add to the case owner string optional the application that owns the cases stack management, observability, or elastic security rule object optional the rule of the alert to add to the case rule id string optional unique identifier rule name string optional name of the resource type string optional the type of the comment or alert to add to the case comment string optional the comment to add to the case id string optional the id of the comment or alert to update version number optional the version of the comment or alert to update input example {"json body" {"alertid" \["8af6ac20 74f6 11ea b83a 553aecdb28b6"],"index" \["8af6ac20 74f6 11ea b83a 553aecdb28b6"],"owner" "cases","rule" {"id" "8af6ac20 74f6 11ea b83a 553aecdb28b6","name" "rule 1"},"type" "alert","comment" "this is a comment"},"path parameters" {"caseid" "8af6ac20 74f6 11ea b83a 553aecdb28b6"}} output parameter type description status code number http status code of the response reason string response reason phrase assignees array output field assignees category object output field category closed at object output field closed at closed by object output field closed by comments array output field comments comments comment string output field comments comment comments created at string output field comments created at comments created by object output field comments created by comments created by email object output field comments created by email comments created by full name object name of the resource comments created by profile uid string unique identifier comments created by username string name of the resource comments id string unique identifier comments owner string output field comments owner comments pushed at object output field comments pushed at comments pushed by object output field comments pushed by comments type string type of the resource comments updated at string output field comments updated at comments updated by object output field comments updated by comments updated by email object output field comments updated by email comments updated by full name object name of the resource comments updated by profile uid string unique identifier comments updated by username string name of the resource output example {"status code" 200,"response headers" {},"reason" "ok","json body" {"assignees" \[],"category"\ null,"closed at"\ null,"closed by"\ null,"comments" \[{}],"connector" {"fields"\ null,"id" "none","name" "none","type" " none"},"created at" "2023 10 24t00 37 03 906z","created by" {"email"\ null,"full name"\ null,"profile uid" "u mgbrof q5bmfcatblxaccwka0k8jvonawsruelyka5e 0","username" "elastic"},"customfields" \[{},{}],"description" "a case description ","duration"\ null,"external service"\ null,"id" "293f1bc update a conversation update a conversation in elastic kibana v9 using the title and id as inputs endpoint url /api/security ai assistant/current user/conversations/{{id}} method put input argument name type required description path parameters id string required parameters for the update a conversation action apiconfig object optional parameter for update a conversation apiconfig actiontypeid string optional the id of the action type apiconfig connectorid string optional the id of the connector apiconfig defaultsystempromptid string optional the id of the default system prompt apiconfig model string optional the model to use for the conversation apiconfig provider string optional the provider to use for the conversation category string optional the category of the conversation excludefromlastconversationstorage boolean optional whether to exclude the conversation from the last conversation storage id string optional the id of the conversation messages array optional response message messages content string optional the content of the message messages role string optional the role of the message messages timestamp string optional the timestamp of the message replacements object optional the replacements for the conversation title string optional the title of the conversation input example {"json body" {"apiconfig" {"actiontypeid" "67890","connectorid" "12345","defaultsystempromptid" "12345","model" "gpt 4o mini","provider" "openai"},"category" "assistant","excludefromlastconversationstorage"\ false,"id" "12345","messages" \[{"content" "hello, how can i assist you today?","role" "system","timestamp" "2023 10 31t12 00 00z"}],"replacements" {},"title" "security discussion"},"path parameters" {"id" "12345"}} output parameter type description status code number http status code of the response reason string response reason phrase apiconfig object output field apiconfig apiconfig actiontypeid string unique identifier apiconfig connectorid string unique identifier category string output field category createdat string output field createdat excludefromlastconversationstorage boolean output field excludefromlastconversationstorage id string unique identifier messages array response message messages content string response content messages role string response message messages timestamp string response message replacements object output field replacements title string output field title updatedat string output field updatedat users array output field users users id string unique identifier users name string name of the resource output example {"status code" 200,"response headers" {},"reason" "ok","json body" {"apiconfig" {"actiontypeid" "09876","connectorid" "54321"},"category" "insights","createdat" "2023 10 31t12 01 00z","excludefromlastconversationstorage"\ true,"id" "abc123","messages" \[{}],"replacements" {},"title" "updated security discussion","updatedat" "2023 10 31t12 31 00z","users" \[{}]}} update a rule update a specific rule in elastic kibana v9 using the rule id, schedule, and name endpoint url /api/alerting/rule/{{id}} method put input argument name type required description path parameters id string required the id of the rule to update actions array optional parameter for update a rule actions frequency object optional parameter for update a rule actions frequency notify when string required indicates how often alerts generate actions actions frequency summary boolean required indicates whether the action is a summary actions frequency throttle string required the throttle interval, which defines how often an alert generates repeated actions it is specified in seconds, minutes, hours, or days and is applicable only if notify when is set to onthrottleinterval actions group string optional the group name, which affects when the action runs (for example, when the threshold is met or when the alert is recovered) each rule type has a list of valid action group names actions id string optional the identifier for the connector saved object actions params object optional the parameters for the action, which are sent to the connector the params are handled as mustache templates and passed a default set of context actions params level string optional parameter for update a rule actions params message string optional response message name string optional the name of the rule while this name does not have to be unique, a distinctive name can help you identify a rule params object optional parameter for update a rule params aggfield string optional parameter for update a rule params aggtype string optional type of the resource params groupby string optional parameter for update a rule params index array optional parameter for update a rule params termfield string optional parameter for update a rule params termsize number optional parameter for update a rule params threshold array optional parameter for update a rule params thresholdcomparator string optional parameter for update a rule params timefield string optional parameter for update a rule params timewindowsize number optional parameter for update a rule params timewindowunit string optional parameter for update a rule schedule object optional parameter for update a rule input example {"json body" {"actions" \[{"frequency" {"notify when" "onactiongroupchange","summary"\ false},"group" "threshold met","id" "96b668d0 a1b6 11ed afdf d39a49596974","params" {"level" "info","message" "rule {{rule name}} is active for group {{context group}} \n\n value {{context value}}\n conditions met {{context conditions}} over {{rule params timewindowsize}}{{rule params timewindowunit}}\n timestamp {{context date}}"}}],"name" "new name","params" {"aggfield" "sheet version","aggtype" "avg","groupby" "top","index" \[" updated index"],"termfield" "name keyword","termsize" 6,"threshold" \[1000],"thresholdcomparator" ">","timefield" "@timestamp","timewindowsize" 5,"timewindowunit" "m"},"schedule" {"interval" "1m"},"tags" \[]},"path parameters" {"id" "96b668d0 a1b6 11ed afdf d39a49596974"}} output parameter type description status code number http status code of the response reason string response reason phrase actions array output field actions actions connector type id string unique identifier actions frequency object output field actions frequency actions frequency notify when string output field actions frequency notify when actions frequency summary boolean output field actions frequency summary actions frequency throttle object output field actions frequency throttle actions group string output field actions group actions id string unique identifier actions params object output field actions params actions params level string output field actions params level actions params message string response message actions uuid string unique identifier api key created by user boolean output field api key created by user api key owner string output field api key owner consumer string output field consumer created at string output field created at created by string output field created by enabled boolean output field enabled execution status object status value execution status last duration number status value execution status last execution date string status value execution status status string status value id string unique identifier output example {"status code" 200,"response headers" {},"reason" "ok","json body" {"actions" \[{}],"api key created by user"\ false,"api key owner" "elastic","consumer" "alerts","created at" "2024 03 26t23 13 20 985z","created by" "elastic","enabled"\ true,"execution status" {"last duration" 52,"last execution date" "2024 03 26t23 22 51 390z","status" "ok"},"id" "ac4e6b90 6be7 11eb ba0d 9b1c1f912d74","last run" {"alerts count" {},"outcome" "succeeded","outcome msg"\ null,"warning"\ null},"mute all"\ false,"muted ale update cases update existing cases in elastic kibana v9 using the provided json body containing case details endpoint url /api/cases method patch input argument name type required description cases array optional parameter for update cases cases assignee array optional an array containing users that are assigned to the case cases category string optional a word or phrase that categorizes the case cases closereason string optional the close reason to sync to attached alerts when closing the case cases connector object optional defines properties for connectors when type is cases webhook cases customfields array optional custom field values for a case any optional custom fields that are not specified in the request are set to null cases description string optional the description for the case cases id string required the identifier for the case cases settings object optional an object that contains the case settings cases severity string optional the severity of the case cases status string optional the status of the case cases tags array optional the words and phrases that help categorize cases it can be an empty array cases title string optional parameter for update cases cases version string required parameter for update cases input example {"json body" {"cases" \[{"assignee" \[{}],"category" "cases","closereason" "false positive","connector" {},"customfields" \[{}],"description" "a case description ","id" "a18b38a0 71b0 11ea a0b2 c51ea50a58e2","settings" {},"severity" "high","status" "open","tags" \["tag 1"],"title" "case title 1","version" "wzizldfd"}]}} output parameter type description status code number http status code of the response reason string response reason phrase output example {"status code" 200,"response headers" {},"reason" "ok","json body" \[{"assignees" \[],"category"\ null,"closed at"\ null,"closed by"\ null,"comments" \[],"connector" {},"created at" "2023 10 13t09 16 17 416z","created by" {},"customfields" \[],"description" "a case description ","duration"\ null,"external service" {},"id" "66b9aa00 94fa 11ea 9f74 e7e108796192","observables" \[],"owner" "cases"}]} response headers header description example content type the media type of the resource application/json date the date and time at which the message was originated thu, 01 jan 2024 00 00 00 gmt