Elastic Kibana V9
Elastic Kibana V9 is a data visualization and exploration tool that enables users to interact with data stored in Elasticsearch.
Elastic Kibana V9 is a powerful data visualization and exploration tool that allows users to analyze and visualize data in real-time. The Elastic Kibana V9 connector for Swimlane Turbine enables seamless integration with Kibana's case management and alert handling capabilities. This integration empowers security teams to automate the creation, management, and updating of cases and alerts, enhancing incident response efficiency. By leveraging Kibana's robust features, Swimlane Turbine users can streamline their security operations, reduce manual efforts, and improve overall security posture.
Limitations
- None to date.
Supported Versions
- This Elastic Kibana V9 connector uses the version 9 API.
Additional Documents
- Documentation Elastic Kibana V9
Prerequisites
Before you can use the Elastic Kibana V9 connector for Turbine, you'll need access to the Elastic Kibana API. This requires the following:
- HTTP Basic authentication using the following parameters:
- URL: The endpoint for your Elastic Kibana instance.
- Username: Your Elastic Kibana username.
- Password: Your Elastic Kibana password.
- API Key authentication using the following parameters:
- URL: The endpoint for your Elastic Kibana instance.
- API Key: A valid API key for accessing Elastic Kibana.
Authentication Methods
API key authentication method:
- URL: The endpoint for accessing the Elastic Kibana API.
- API Key: A unique key provided by Elastic for authenticating API requests.
HTTP Basic authentication method:
- URL: The endpoint for accessing the Elastic Kibana API.
- Username: Your Elastic Kibana account username.
- Password: The password associated with your Elastic Kibana account.
Capabilities
This Connector provides the following capabilities:
- Add a Case Comment or Alert
- Attach a File to a Case
- Create a Case
- Create a Conversation
- Create a Model Response
- Create a rule
- Delete Cases
- Delete a Case Comment or Alert
- Delete a Conversation
- Delete a Rule
- Disable a Rule
- Enable a Rule
- Get All Alerts for a Case
- Get Conversations
- Get Information About Rules ... and so on
Add a Case Comment or Alert
- Add a comment or alert to a case in Elastic Kibana V9 using the specified caseId as a path parameter and provide additional details in the JSON body. Click Here
Attach a File to a Case
- Attach a file to a case in Elastic Kibana V9 using the caseId and file details provided in the JSON body. Click Here
Create a Case
- Create a case in Elastic Kibana V9 with specified connector, description, owner, settings, tags, and title. Click Here
Create a Conversation
- Initiate a new conversation in Elastic Kibana V9 using the provided title in the JSON body. Click Here
Create a Model Response
- Create a model response in Elastic Kibana V9 using connectorId, persist, and messages. This action requires json_body and content_references_disabled parameters. Click Here
Create a rule
- Create a rule in Elastic Kibana V9 using specified JSON body and path parameters, including the rule ID. Click Here
Delete Cases
- Delete cases in Elastic Kibana V9 to manage and organize your case data efficiently. Click Here
Delete a Case Comment or Alert
- Delete a case comment or alert in Elastic Kibana V9 using the specified caseId and commentId as path parameters. Click Here
Delete a Conversation
- Permanently delete an existing conversation in Elastic Kibana V9 using the conversation ID as a path parameter. Click Here
Delete a Rule
- Delete a rule in Elastic Kibana V9 using the specified rule ID as a path parameter. Click Here
Disable a Rule
- Disable a rule in Elastic Kibana V9 using the rule ID and untrack status. Click Here
Enable a Rule
- Enable a specific rule in Elastic Kibana V9 using the rule ID as a path parameter. Click Here
Get All Alerts for a Case
- Get all alerts associated with a specific case in Elastic Kibana V9. Click Here
Get Conversations
- Fetch and display conversations from Elastic Kibana V9 for analysis and review. Click Here
Get Information About Rules
- Get information about rules. Click Here
Get a Conversation
- Retrieve details of an existing conversation in Elastic Kibana V9 using the unique conversation ID. Click Here
Search Cases
- Search for cases in Elastic Kibana V9 and retrieve relevant information. Click Here
Update Cases
- Update existing cases in Elastic Kibana V9 using the provided JSON body containing case details. Click Here
Update a Case Comment or Alert
- Update a case comment or alert in Elastic Kibana V9 using the specified caseId and JSON body. Click Here
Update a Conversation
- Update a conversation in Elastic Kibana V9 using the title and ID as inputs. Click Here
Update a Rule
- Update a specific rule in Elastic Kibana V9 using the rule ID, schedule, and name. Click Here
Configurations
Elastick Kibana V9 API Key Authentication
Authenticates using an API Key
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
port | Host port to use. | number | Optional |
space | The Kibana space ID to target. Defaults to the 'default' space if not provided. | string | Optional |
x-apikey | API key | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Elastick Kibana V9 HTTP Basic Authentication
Authenticates using username and password.
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host | string | Required |
port | Host port to use. | number | Optional |
space | The Kibana space ID to target. Defaults to the 'default' space if not provided. | string | Optional |
username | Username | string | Required |
password | Password | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Add a Case Comment or Alert
Add a comment or alert to a case in Elastic Kibana V9 using the specified caseId as a path parameter and provide additional details in the JSON body.
Endpoint
- URL: /api/cases/{{caseId}}/comments
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.caseId | string | Required | The ID of the case to add a comment or alert to. |
alertId | array | Optional | The ID of the alert to add to the case. |
index | array | Optional | The index of the alert to add to the case. |
owner | string | Optional | The application that owns the cases - Stack Management, Observability, or Elastic Security. |
rule | object | Optional | The rule of the alert to add to the case. |
rule.id | string | Optional | Unique identifier |
rule.name | string | Optional | Name of the resource |
type | string | Optional | The type of the comment or alert to add to the case. |
comment | string | Optional | The comment to add to the case. |
Input Example
{"json_body":{"alertId":["8af6ac20-74f6-11ea-b83a-553aecdb28b6"],"index":["8af6ac20-74f6-11ea-b83a-553aecdb28b6"],"owner":"cases","rule":{"id":"8af6ac20-74f6-11ea-b83a-553aecdb28b6","name":"Rule 1"},"type":"alert","comment":"This is a comment"},"path_parameters":{"caseId":"8af6ac20-74f6-11ea-b83a-553aecdb28b6"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
assignees | array | Output field: assignees |
category | object | Output field: category |
closed_at | object | Output field: closed_at |
closed_by | object | Output field: closed_by |
comments | array | Output field: comments |
comments.comment | string | Output field: comments.comment |
comments.created_at | string | Output field: comments.created_at |
comments.created_by | object | Output field: comments.created_by |
comments.created_by.email | object | Output field: comments.created_by.email |
comments.created_by.full_name | object | Name of the resource |
comments.created_by.profile_uid | string | Unique identifier |
comments.created_by.username | string | Name of the resource |
comments.id | string | Unique identifier |
comments.owner | string | Output field: comments.owner |
comments.pushed_at | object | Output field: comments.pushed_at |
comments.pushed_by | object | Output field: comments.pushed_by |
comments.type | string | Type of the resource |
comments.updated_at | object | Output field: comments.updated_at |
comments.updated_by | object | Output field: comments.updated_by |
comments.version | string | Output field: comments.version |
connector | object | Output field: connector |
connector.fields | object | Output field: connector.fields |
connector.id | string | Unique identifier |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"assignees":[],"category":null,"closed_at":null,"closed_by":null,"comments":[{}],"connector":{"fields":null,"id":"none","name":"none","type":".none"},"created_at":"2022-03-24T00:37:03.906Z","created_by":{"email":null,"full_name":null,"profile_uid":"u_mGBROF_q5bmFCATbLXAcCwKa0k8JvONAwSruelyKA5E_0","username":"elastic"},"customFields":[{},{}],"description":"A case description.","duration":null,"external_service":null,"id":"293f1bc...
Attach a File to a Case
Attach a file to a case in Elastic Kibana V9 using the specified caseId and file details provided in the JSON body.
Endpoint
- URL: /api/cases/{{caseId}}/files
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.caseId | string | Required | The ID of the case to attach a file to. |
file | object | Optional | Parameter for Attach a File to a Case |
file.file_name | string | Optional | Name of the resource |
file.file | string | Optional | Parameter for Attach a File to a Case |
Input Example
{"json_body":{"file":{"file_name":"test.txt","file":"VGhpcyBpcyBhIHRlc3QgZmlsZS4="}},"path_parameters":{"caseId":"9c235210-6834-11ea-a78c-6ffb38a34414"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
assignees | array | Output field: assignees |
category | object | Output field: category |
closed_at | object | Output field: closed_at |
closed_by | object | Output field: closed_by |
comments | array | Output field: comments |
comments.comment | string | Output field: comments.comment |
comments.created_at | string | Output field: comments.created_at |
comments.created_by | object | Output field: comments.created_by |
comments.created_by.email | object | Output field: comments.created_by.email |
comments.created_by.full_name | object | Name of the resource |
comments.created_by.profile_uid | string | Unique identifier |
comments.created_by.username | string | Name of the resource |
comments.id | string | Unique identifier |
comments.owner | string | Output field: comments.owner |
comments.pushed_at | object | Output field: comments.pushed_at |
comments.pushed_by | object | Output field: comments.pushed_by |
comments.type | string | Type of the resource |
comments.updated_at | object | Output field: comments.updated_at |
comments.updated_by | object | Output field: comments.updated_by |
comments.version | string | Output field: comments.version |
connector | object | Output field: connector |
connector.fields | object | Output field: connector.fields |
connector.id | string | Unique identifier |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"assignees":[],"category":null,"closed_at":null,"closed_by":null,"comments":[{}],"connector":{"fields":null,"id":"none","name":"none","type":".none"},"created_at":"2022-03-24T00:37:03.906Z","created_by":{"email":null,"full_name":null,"profile_uid":"u_mGBROF_q5bmFCATbLXAcCwKa0k8JvONAwSruelyKA5E_0","username":"elastic"},"customFields":[{},{}],"description":"A case description.","duration":null,"external_service":null,"id":"293f1bc...
Create a Case
Create a case in Elastic Kibana V9 using specified connector, description, owner, settings, tags, and title.
Endpoint
- URL: /api/cases
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
assignee | array | Optional | An array containing users that are assigned to the case. |
category | string | Optional | A word or phrase that categorizes the case. |
connector | object | Optional | Defines properties for connectors when type is .none. |
customFields | array | Optional | Custom field values for a case. Any optional custom fields that are not specified in the request are set to null. |
description | string | Optional | The description for the case. |
owner | string | Optional | The application that owns the cases - Stack Management, Observability, or Elastic Security. |
settings | object | Optional | An object that contains the case settings. |
severity | string | Optional | The severity of the case. |
tags | array | Optional | The words and phrases that help categorize cases. It can be an empty array. |
title | string | Optional | A title for the case. |
Input Example
{"json_body":{"assignee":[{}],"category":"cases","connector":{},"customFields":[{}],"description":"A case description.","owner":"cases","settings":{},"severity":"high","tags":["tag-1"],"title":"Case title 1"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
assignees | array | Output field: assignees |
closed_at | object | Output field: closed_at |
closed_by | object | Output field: closed_by |
comments | array | Output field: comments |
connector | object | Output field: connector |
connector.fields | object | Output field: connector.fields |
connector.fields.issueType | string | Type of the resource |
connector.fields.parent | object | Output field: connector.fields.parent |
connector.fields.priority | string | Output field: connector.fields.priority |
connector.id | string | Unique identifier |
connector.name | string | Name of the resource |
connector.type | string | Type of the resource |
created_at | string | Output field: created_at |
created_by | object | Output field: created_by |
created_by.email | object | Output field: created_by.email |
created_by.full_name | object | Name of the resource |
created_by.profile_uid | string | Unique identifier |
created_by.username | string | Name of the resource |
customFields | array | Output field: customFields |
customFields.key | string | Output field: customFields.key |
customFields.type | string | Type of the resource |
customFields.value | object | Value for the parameter |
description | string | Output field: description |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"assignees":[],"closed_at":null,"closed_by":null,"comments":[],"connector":{"fields":{},"id":"131d4448-abe0-4789-939d-8ef60680b498","name":"My connector","type":".jira"},"created_at":"2022-10-13T15:33:50.604Z","created_by":{"email":null,"full_name":null,"profile_uid":"u_mGBROF_q5bmFCATbLXAcCwKa0k8JvONAwSruelyKA5E_0","username":"elastic"},"customFields":[{},{}],"description":"A case description.","duration":null,"external_service...
Create a Conversation
Initiate a new conversation in Elastic Kibana V9 using the provided title in the JSON body.
Endpoint
- URL: /api/security_ai_assistant/current_user/conversations
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
apiConfig | object | Optional | Parameter for Create a Conversation |
apiConfig.actionTypeId | string | Optional | The ID of the action type. |
apiConfig.connectorId | string | Optional | The ID of the connector. |
apiConfig.defaultSystemPromptId | string | Optional | The ID of the default system prompt. |
apiConfig.model | string | Optional | The model to use for the conversation. |
apiConfig.provider | string | Optional | The provider to use for the conversation. |
category | string | Optional | The category of the conversation. |
excludeFromLastConversationStorage | boolean | Optional | Whether to exclude the conversation from the last conversation storage. |
id | string | Optional | The ID of the conversation. |
messages | array | Optional | Response message |
messages.content | string | Optional | The content of the message. |
messages.role | string | Optional | The role of the message. |
messages.timestamp | string | Optional | The timestamp of the message. |
replacements | object | Optional | The replacements for the conversation. |
title | string | Optional | The title of the conversation. |
Input Example
{"json_body":{"apiConfig":{"actionTypeId":"67890","connectorId":"12345","defaultSystemPromptId":"12345","model":"gpt-4o-mini","provider":"openai"},"category":"assistant","excludeFromLastConversationStorage":false,"id":"12345","messages":[{"content":"Hello, how can I assist you today?","role":"system","timestamp":"2023-10-31T12:00:00Z"}],"replacements":{},"title":"Security Discussion"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
apiConfig | object | Output field: apiConfig |
apiConfig.actionTypeId | string | Unique identifier |
apiConfig.connectorId | string | Unique identifier |
category | string | Output field: category |
createdAt | string | Output field: createdAt |
excludeFromLastConversationStorage | boolean | Output field: excludeFromLastConversationStorage |
id | string | Unique identifier |
messages | array | Response message |
messages.content | string | Response content |
messages.role | string | Response message |
messages.timestamp | string | Response message |
replacements | object | Output field: replacements |
title | string | Output field: title |
updatedAt | string | Output field: updatedAt |
users | array | Output field: users |
users.id | string | Unique identifier |
users.name | string | Name of the resource |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"apiConfig":{"actionTypeId":"67890","connectorId":"12345"},"category":"assistant","createdAt":"2023-10-31T12:01:00Z","excludeFromLastConversationStorage":false,"id":"abc123","messages":[{}],"replacements":{},"title":"Security Discussion","updatedAt":"2023-10-31T12:01:00Z","users":[{}]}}
Create a Model Response
Create a model response in Elastic Kibana V9 using connectorId, persist, and messages. Requires json_body and content_references_disabled parameters.
Endpoint
- URL: /api/security_ai_assistant/chat/complete
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.content_references_disabled | boolean | Required | Whether to disable content references. |
connectorId | string | Optional | The ID of the connector. |
conversationId | string | Optional | The ID of the conversation. |
isStream | boolean | Optional | Whether to stream the response. |
langSmithApiKey | string | Optional | The API key for the LangSmith project. |
langSmithProject | string | Optional | The project for the LangSmith API key. |
messages | array | Optional | Response message |
messages.content | string | Optional | The content of the message. |
messages.data | object | Optional | The data of the message. |
messages.data.user_id | string | Optional | The ID of the user. |
messages.fields_to_anonymize | array | Optional | The fields to anonymize. |
messages.role | string | Optional | The role of the message. |
model | string | Optional | The model to use for the response. |
persist | boolean | Optional | Whether to persist the response. |
promptId | string | Optional | The ID of the prompt. |
responseLanguage | string | Optional | The language of the response. |
Input Example
{"parameters":{"content_references_disabled":false},"json_body":{"connectorId":"conn-001","conversationId":"abc123","isStream":true,"langSmithApiKey":"sk-abc123","langSmithProject":"security_ai_project","messages":[{"content":"What are some common phishing techniques?","data":{"user_id":"user_789"},"fields_to_anonymize":["user.name","source.ip"],"role":"user"}],"model":"gpt-4","persist":true,"promptId":"prompt_456","responseLanguage":"en"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{}}
Create a rule
Create a rule in Elastic Kibana V9 using specified JSON body and path parameters, including the rule ID.
Endpoint
- URL: /api/alerting/rule/{{id}}
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | The ID of the rule. |
actions | array | Optional | The actions to perform when the rule is triggered. |
alert_delay | object | Optional | The delay before the alert is triggered. |
artifacts | object | Optional | The artifacts to attach to the alert. |
enabled | boolean | Optional | Whether the rule is enabled. |
consumer | string | Optional | The consumer of the rule. |
name | string | Optional | The name of the rule. |
params | object | Optional | The parameters of the rule. |
rule_type_id | string | Optional | The type of the rule. |
schedule | object | Optional | The schedule of the rule. |
schedule.interval | string | Optional | The interval of the schedule. |
Input Example
{"json_body":{"actions":[{}],"alert_delay":{},"artifacts":{},"enabled":true,"consumer":"stackAlerts","name":"my Elasticsearch query ESQL rule","params":{},"rule_type_id":".es-query","schedule":{"interval":"1d"}},"path_parameters":{"id":"d0db1fe0-78d6-11ee-9177-f7d404c8c945"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
actions | array | Output field: actions |
actions.connector_type_id | string | Unique identifier |
actions.frequency | object | Output field: actions.frequency |
actions.frequency.notify_when | string | Output field: actions.frequency.notify_when |
actions.frequency.summary | boolean | Output field: actions.frequency.summary |
actions.frequency.throttle | object | Output field: actions.frequency.throttle |
actions.group | string | Output field: actions.group |
actions.id | string | Unique identifier |
actions.params | object | Output field: actions.params |
actions.params.level | string | Output field: actions.params.level |
actions.params.message | string | Response message |
actions.uuid | string | Unique identifier |
api_key_created_by_user | boolean | Output field: api_key_created_by_user |
api_key_owner | string | Output field: api_key_owner |
consumer | string | Output field: consumer |
created_at | string | Output field: created_at |
created_by | string | Output field: created_by |
enabled | boolean | Output field: enabled |
execution_status | object | Status value |
execution_status.last_execution_date | string | Status value |
execution_status.status | string | Status value |
id | string | Unique identifier |
mute_all | boolean | Output field: mute_all |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"actions":[{}],"api_key_created_by_user":false,"api_key_owner":"elastic","consumer":"stackAlerts","created_at":"2023-11-01T19:00:10.453Z","created_by":"elastic","enabled":true,"execution_status":{"last_execution_date":"2023-11-01T19:00:10.453Z","status":"pending"},"id":"e0d62360-78e8-11ee-9177-f7d404c8c945","mute_all":false,"muted_alert_ids":[],"name":"my Elasticsearch query ESQL rule","notify_when":null,"params":{"aggType":"cou...
Delete a Case Comment or Alert
Delete a case comment or alert in Elastic Kibana V9 using the specified caseId and commentId as path parameters.
Endpoint
- URL: /api/cases/{{caseId}}/comments/{{commentId}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.caseId | string | Required | The ID of the case to delete a comment or alert from. |
path_parameters.commentId | string | Required | The ID of the comment to delete from the case. |
Input Example
{"path_parameters":{"caseId":"8af6ac20-74f6-11ea-b83a-553aecdb28b6","commentId":"8af6ac20-74f6-11ea-b83a-553aecdb28b6"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"status_code":204,"response_headers":{},"reason":"No Content","response_text":""}
Delete a Conversation
Permanently delete an existing conversation in Elastic Kibana V9 using the conversation ID as a path parameter.
Endpoint
- URL: /api/security_ai_assistant/current_user/conversations/{{id}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Delete a Conversation action |
Input Example
{"path_parameters":{"id":"12345"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
apiConfig | object | Output field: apiConfig |
apiConfig.actionTypeId | string | Unique identifier |
apiConfig.connectorId | string | Unique identifier |
category | string | Output field: category |
createdAt | string | Output field: createdAt |
excludeFromLastConversationStorage | boolean | Output field: excludeFromLastConversationStorage |
id | string | Unique identifier |
messages | array | Response message |
messages.content | string | Response content |
messages.role | string | Response message |
messages.timestamp | string | Response message |
replacements | object | Output field: replacements |
title | string | Output field: title |
updatedAt | string | Output field: updatedAt |
users | array | Output field: users |
users.id | string | Unique identifier |
users.name | string | Name of the resource |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"apiConfig":{"actionTypeId":"67890","connectorId":"12345"},"category":"assistant","createdAt":"2023-10-31T12:01:00Z","excludeFromLastConversationStorage":false,"id":"abc123","messages":[{}],"replacements":{},"title":"Deleted Security Discussion","updatedAt":"2023-10-31T12:01:00Z","users":[{}]}}
Delete a Rule
Delete a rule in Elastic Kibana V9 using the specified rule ID as a path parameter.
Endpoint
- URL: /api/alerting/rule/{{id}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Delete a Rule action |
Input Example
{"path_parameters":{"id":"96b668d0-a1b6-11ed-afdf-d39a49596974"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"status_code":204,"response_headers":{},"reason":"No Content","response_text":""}
Delete Cases
Delete cases in Elastic Kibana V9 to manage and organize your case data efficiently.
Endpoint
- URL: /api/cases
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.ids | array | Optional | Parameters for the Delete Cases action |
Input Example
{"parameters":{"ids":["131d4448-abe0-4789-939d-8ef60680b498"]}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"status_code":204,"response_headers":{},"reason":"No Content","response_text":""}
Disable a Rule
Disable a rule in Elastic Kibana V9 using the rule ID and untrack status. Requires path parameters and JSON body.
Endpoint
- URL: /api/alerting/rule/{{id}}/_disable
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | The identifier for the rule. |
untrack | boolean | Optional | Defines whether this rule's alerts should be untracked. |
Input Example
{"json_body":{"untrack":true},"path_parameters":{"id":"96b668d0-a1b6-11ed-afdf-d39a49596974"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"status_code":204,"response_headers":{},"reason":"No Content","response_text":""}
Enable a Rule
Enable a specific rule in Elastic Kibana V9 using the rule ID as a path parameter.
Endpoint
- URL: /api/alerting/rule/{{id}}/_enable
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | The identifier for the rule. |
Input Example
{"path_parameters":{"id":"96b668d0-a1b6-11ed-afdf-d39a49596974"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"status_code":204,"response_headers":{},"reason":"No Content","response_text":""}
Get a Conversation
Retrieve details of an existing conversation in Elastic Kibana V9 using the unique conversation ID.
Endpoint
- URL: /api/security_ai_assistant/current_user/conversations/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | The ID of the conversation to get. |
Input Example
{"path_parameters":{"id":"12345"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
apiConfig | object | Output field: apiConfig |
apiConfig.actionTypeId | string | Unique identifier |
apiConfig.connectorId | string | Unique identifier |
category | string | Output field: category |
createdAt | string | Output field: createdAt |
excludeFromLastConversationStorage | boolean | Output field: excludeFromLastConversationStorage |
id | string | Unique identifier |
messages | array | Response message |
messages.content | string | Response content |
messages.role | string | Response message |
messages.timestamp | string | Response message |
replacements | object | Output field: replacements |
title | string | Output field: title |
updatedAt | string | Output field: updatedAt |
users | array | Output field: users |
users.id | string | Unique identifier |
users.name | string | Name of the resource |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"apiConfig":{"actionTypeId":"67890","connectorId":"12345"},"category":"assistant","createdAt":"2023-10-31T12:01:00Z","excludeFromLastConversationStorage":false,"id":"abc123","messages":[{}],"replacements":{},"title":"Security Discussion","updatedAt":"2023-10-31T12:01:00Z","users":[{}]}}
Get All Alerts for a Case
Get all alerts associated with a specific case in Elastic Kibana V9 using the caseId path parameter.
Endpoint
- URL: /api/cases/{{caseId}}/alerts
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.caseId | string | Required | Parameters for the Get All Alerts for a Case action |
Input Example
{"path_parameters":{"caseId":"f6a7d0c3-d52d-432c-b2e6-447cd7fce04d"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":[{"attached_at":"2022-07-25T20:09:40.963Z","id":"f6a7d0c3-d52d-432c-b2e6-447cd7fce04d","index":".alerts-observability.logs.alerts-default"}]}
Get Conversations
Fetch and display conversations from Elastic Kibana V9 for analysis and review.
Endpoint
- URL: /api/security_ai_assistant/current_user/conversations/_find
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.fields | string | Optional | A list of fields to include in the response. If omitted, all fields are returned. |
parameters.filter | string | Optional | A search query to filter the conversations. Can match against titles, messages, or other conversation attributes. |
parameters.sort_field | string | Optional | The field by which to sort the results. Valid fields are created_at, title, and updated_at. |
parameters.sort_order | string | Optional | The order in which to sort the results. Can be either asc for ascending or desc for descending. |
parameters.page | number | Optional | The page number of the results to retrieve. |
parameters.page_size | number | Optional | The number of conversations to return per page. |
parameters.is_owner | boolean | Optional | Whether to return conversations that the current user owns. If true, only conversations owned by the user are returned. |
Input Example
{"parameters":{"fields":"title","filter":"title:Security Discussion","sort_field":"title","sort_order":"asc","page":1,"page_size":10,"is_owner":true}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{}}
Get Information About Rules
Get detailed information about rules in Elastic Kibana V9, including their configurations and statuses.
Endpoint
- URL: /api/alerting/rules/_find
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.per_page | number | Optional | The number of rules to return per page. |
parameters.page | number | Optional | The page number to return. |
parameters.search | string | Optional | An Elasticsearch simple_query_string query that filters the objects in the response. |
parameters.default_search_operator | string | Optional | The default operator to use for the simple_query_string. |
parameters.search_fields | string | Optional | The fields to perform the simple_query_string parsed query against. |
parameters.sort_field | string | Optional | Determines which field is used to sort the results. The field must exist in the attributes key of the response. |
parameters.sort_order | string | Optional | Determines the sort order. |
parameters.fields | string | Optional | The fields to return in the attributes key of the response. |
parameters.filter | string | Optional | A KQL string that you filter with an attribute from your saved object. It should look like savedObjectType.updatedAt > 2018-12-22. |
parameters.filter_consumers | string | Optional | List of consumers to filter. |
Input Example
{"parameters":{"per_page":10,"page":1,"search":"test","default_search_operator":"AND","search_fields":"name,description","sort_field":"name","sort_order":"asc","fields":"name,description","filter":"name:test","filter_consumers":"test"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | array | Response data |
data.actions | array | Response data |
data.actions.frequency | object | Response data |
data.actions.frequency.notify_when | string | Response data |
data.actions.frequency.summary | boolean | Response data |
data.actions.frequency.throttle | object | Response data |
data.actions.group | string | Response data |
data.actions.id | string | Response data |
data.actions.params | object | Response data |
data.actions.params.connector_type_id | string | Response data |
data.actions.params.level | string | Response data |
data.actions.params.message | string | Response data |
data.actions.uuid | string | Response data |
data.api_key_created_by_user | boolean | Response data |
data.api_key_owner | string | Response data |
data.consumer | string | Response data |
data.created_at | string | Response data |
data.created_by | string | Response data |
data.enabled | boolean | Response data |
data.execution_status | object | Response data |
data.execution_status.last_duration | number | Response data |
data.execution_status.last_execution_date | string | Response data |
data.execution_status.status | string | Response data |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"data":[{}],"page":1,"per_page":10,"total":1}}
Search Cases
Search for cases in Elastic Kibana V9 and retrieve relevant information.
Endpoint
- URL: /api/cases/_find
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.assignees | string | Optional | Filters the returned cases by assignees. Valid values are none or unique identifiers for the user profiles. These identifiers can be found by using the suggest user profile API. |
parameters.category | string | Optional | Filters the returned cases by category. |
parameters.defaultSearchOperator | string | Optional | he default operator to use for the simple_query_string. |
parameters.from | string | Optional | Returns only cases that were created after a specific date. The date must be specified as a KQL data range or date match expression. |
parameters.owner | string | Optional | A filter to limit the response to a specific set of applications. If this parameter is omitted, the response contains information about all the cases that the user has access to read. |
parameters.page | number | Optional | The page number to return. |
parameters.perPage | number | Optional | The number of cases to return per page. Maximum is 100. |
parameters.reporters | array | Optional | Filters the returned cases by the user name of the reporter. |
parameters.search | string | Optional | An Elasticsearch simple_query_string query that filters the objects in the response. |
parameters.searchFields | array | Optional | The fields to perform the simple_query_string parsed query against. |
parameters.severity | string | Optional | The severity of the case. |
parameters.sortField | string | Optional | The field to sort the results by. |
parameters.sortOrder | string | Optional | The order to sort the results by. |
parameters.status | string | Optional | TFilters the returned cases by state. |
parameters.tags | array | Optional | Filters the returned cases by tags. |
parameters.to | string | Optional | Returns only cases that were created before a specific date. The date must be specified as a KQL data range or date match expression. |
Input Example
{"parameters":{"assignees":"u_mGBROF_q5bmFCATbLXAcCwKa0k8JvONAwSruelyKA5E_0","category":"cases","defaultSearchOperator":"OR","from":"now-7d","owner":"cases","page":1,"perPage":20,"reporters":["elastic"],"search":"Case title 1","searchFields":["title"],"severity":"high","sortField":"createdAt","sortOrder":"desc","status":"open","tags":["tag-1"],"to":"now"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
cases | array | Output field: cases |
cases.assignees | array | Output field: cases.assignees |
cases.category | object | Output field: cases.category |
cases.closed_at | object | Output field: cases.closed_at |
cases.closed_by | object | Output field: cases.closed_by |
cases.comments | array | Output field: cases.comments |
cases.connector | object | Output field: cases.connector |
cases.connector.fields | object | Output field: cases.connector.fields |
cases.connector.id | string | Unique identifier |
cases.connector.name | string | Name of the resource |
cases.connector.type | string | Type of the resource |
cases.created_at | string | Output field: cases.created_at |
cases.created_by | object | Output field: cases.created_by |
cases.created_by.email | object | Output field: cases.created_by.email |
cases.created_by.full_name | object | Name of the resource |
cases.created_by.profile_uid | string | Unique identifier |
cases.created_by.username | string | Name of the resource |
cases.customFields | array | Output field: cases.customFields |
cases.customFields.key | string | Output field: cases.customFields.key |
cases.customFields.type | string | Type of the resource |
cases.customFields.value | object | Value for the parameter |
cases.description | string | Output field: cases.description |
cases.duration | object | Output field: cases.duration |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"cases":[{}],"count_closed_cases":0,"count_in_progress_cases":0,"count_open_cases":1,"page":1,"per_page":5,"total":1}}
Update a Case Comment or Alert
Update a case comment or alert in Elastic Kibana V9 using the specified caseId and JSON body.
Endpoint
- URL: /api/cases/{{caseId}}/comments
- Method: PATCH
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.caseId | string | Required | The ID of the case to add a comment or alert to. |
alertId | array | Optional | The ID of the alert to add to the case. |
index | array | Optional | The index of the alert to add to the case. |
owner | string | Optional | The application that owns the cases - Stack Management, Observability, or Elastic Security. |
rule | object | Optional | The rule of the alert to add to the case. |
rule.id | string | Optional | Unique identifier |
rule.name | string | Optional | Name of the resource |
type | string | Optional | The type of the comment or alert to add to the case. |
comment | string | Optional | The comment to add to the case. |
id | string | Optional | The ID of the comment or alert to update. |
version | number | Optional | The version of the comment or alert to update. |
Input Example
{"json_body":{"alertId":["8af6ac20-74f6-11ea-b83a-553aecdb28b6"],"index":["8af6ac20-74f6-11ea-b83a-553aecdb28b6"],"owner":"cases","rule":{"id":"8af6ac20-74f6-11ea-b83a-553aecdb28b6","name":"Rule 1"},"type":"alert","comment":"This is a comment"},"path_parameters":{"caseId":"8af6ac20-74f6-11ea-b83a-553aecdb28b6"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
assignees | array | Output field: assignees |
category | object | Output field: category |
closed_at | object | Output field: closed_at |
closed_by | object | Output field: closed_by |
comments | array | Output field: comments |
comments.comment | string | Output field: comments.comment |
comments.created_at | string | Output field: comments.created_at |
comments.created_by | object | Output field: comments.created_by |
comments.created_by.email | object | Output field: comments.created_by.email |
comments.created_by.full_name | object | Name of the resource |
comments.created_by.profile_uid | string | Unique identifier |
comments.created_by.username | string | Name of the resource |
comments.id | string | Unique identifier |
comments.owner | string | Output field: comments.owner |
comments.pushed_at | object | Output field: comments.pushed_at |
comments.pushed_by | object | Output field: comments.pushed_by |
comments.type | string | Type of the resource |
comments.updated_at | string | Output field: comments.updated_at |
comments.updated_by | object | Output field: comments.updated_by |
comments.updated_by.email | object | Output field: comments.updated_by.email |
comments.updated_by.full_name | object | Name of the resource |
comments.updated_by.profile_uid | string | Unique identifier |
comments.updated_by.username | string | Name of the resource |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"assignees":[],"category":null,"closed_at":null,"closed_by":null,"comments":[{}],"connector":{"fields":null,"id":"none","name":"none","type":".none"},"created_at":"2023-10-24T00:37:03.906Z","created_by":{"email":null,"full_name":null,"profile_uid":"u_mGBROF_q5bmFCATbLXAcCwKa0k8JvONAwSruelyKA5E_0","username":"elastic"},"customFields":[{},{}],"description":"A case description.","duration":null,"external_service":null,"id":"293f1bc...
Update a Conversation
Update a conversation in Elastic Kibana V9 using the title and ID as inputs.
Endpoint
- URL: /api/security_ai_assistant/current_user/conversations/{{id}}
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Update a Conversation action |
apiConfig | object | Optional | Parameter for Update a Conversation |
apiConfig.actionTypeId | string | Optional | The ID of the action type. |
apiConfig.connectorId | string | Optional | The ID of the connector. |
apiConfig.defaultSystemPromptId | string | Optional | The ID of the default system prompt. |
apiConfig.model | string | Optional | The model to use for the conversation. |
apiConfig.provider | string | Optional | The provider to use for the conversation. |
category | string | Optional | The category of the conversation. |
excludeFromLastConversationStorage | boolean | Optional | Whether to exclude the conversation from the last conversation storage. |
id | string | Optional | The ID of the conversation. |
messages | array | Optional | Response message |
messages.content | string | Optional | The content of the message. |
messages.role | string | Optional | The role of the message. |
messages.timestamp | string | Optional | The timestamp of the message. |
replacements | object | Optional | The replacements for the conversation. |
title | string | Optional | The title of the conversation. |
Input Example
{"json_body":{"apiConfig":{"actionTypeId":"67890","connectorId":"12345","defaultSystemPromptId":"12345","model":"gpt-4o-mini","provider":"openai"},"category":"assistant","excludeFromLastConversationStorage":false,"id":"12345","messages":[{"content":"Hello, how can I assist you today?","role":"system","timestamp":"2023-10-31T12:00:00Z"}],"replacements":{},"title":"Security Discussion"},"path_parameters":{"id":"12345"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
apiConfig | object | Output field: apiConfig |
apiConfig.actionTypeId | string | Unique identifier |
apiConfig.connectorId | string | Unique identifier |
category | string | Output field: category |
createdAt | string | Output field: createdAt |
excludeFromLastConversationStorage | boolean | Output field: excludeFromLastConversationStorage |
id | string | Unique identifier |
messages | array | Response message |
messages.content | string | Response content |
messages.role | string | Response message |
messages.timestamp | string | Response message |
replacements | object | Output field: replacements |
title | string | Output field: title |
updatedAt | string | Output field: updatedAt |
users | array | Output field: users |
users.id | string | Unique identifier |
users.name | string | Name of the resource |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"apiConfig":{"actionTypeId":"09876","connectorId":"54321"},"category":"insights","createdAt":"2023-10-31T12:01:00Z","excludeFromLastConversationStorage":true,"id":"abc123","messages":[{}],"replacements":{},"title":"Updated Security Discussion","updatedAt":"2023-10-31T12:31:00Z","users":[{}]}}
Update a Rule
Update a specific rule in Elastic Kibana V9 using the rule ID, schedule, and name.
Endpoint
- URL: /api/alerting/rule/{{id}}
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | The ID of the rule to update. |
actions | array | Optional | Parameter for Update a Rule |
actions.frequency | object | Optional | Parameter for Update a Rule |
actions.frequency.notify_when | string | Required | Indicates how often alerts generate actions. |
actions.frequency.summary | boolean | Required | Indicates whether the action is a summary. |
actions.frequency.throttle | string | Required | The throttle interval, which defines how often an alert generates repeated actions. It is specified in seconds, minutes, hours, or days and is applicable only if notify_when is set to onThrottleInterval. |
actions.group | string | Optional | The group name, which affects when the action runs (for example, when the threshold is met or when the alert is recovered). Each rule type has a list of valid action group names. |
actions.id | string | Optional | The identifier for the connector saved object. |
actions.params | object | Optional | The parameters for the action, which are sent to the connector. The params are handled as Mustache templates and passed a default set of context. |
actions.params.level | string | Optional | Parameter for Update a Rule |
actions.params.message | string | Optional | Response message |
name | string | Optional | The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. |
params | object | Optional | Parameter for Update a Rule |
params.aggField | string | Optional | Parameter for Update a Rule |
params.aggType | string | Optional | Type of the resource |
params.groupBy | string | Optional | Parameter for Update a Rule |
params.index | array | Optional | Parameter for Update a Rule |
params.termField | string | Optional | Parameter for Update a Rule |
params.termSize | number | Optional | Parameter for Update a Rule |
params.threshold | array | Optional | Parameter for Update a Rule |
params.thresholdComparator | string | Optional | Parameter for Update a Rule |
params.timeField | string | Optional | Parameter for Update a Rule |
params.timeWindowSize | number | Optional | Parameter for Update a Rule |
params.timeWindowUnit | string | Optional | Parameter for Update a Rule |
schedule | object | Optional | Parameter for Update a Rule |
Input Example
{"json_body":{"actions":[{"frequency":{"notify_when":"onActionGroupChange","summary":false},"group":"threshold met","id":"96b668d0-a1b6-11ed-afdf-d39a49596974","params":{"level":"info","message":"Rule {{rule.name}} is active for group {{context.group}}:\n\n- Value: {{context.value}}\n- Conditions Met: {{context.conditions}} over {{rule.params.timeWindowSize}}{{rule.params.timeWindowUnit}}\n- Timestamp: {{context.date}}"}}],"name":"new name","params":{"aggField":"sheet.version","aggType":"avg","groupBy":"top","index":[".updated-index"],"termField":"name.keyword","termSize":6,"threshold":[1000],"thresholdComparator":">","timeField":"@timestamp","timeWindowSize":5,"timeWindowUnit":"m"},"schedule":{"interval":"1m"},"tags":[]},"path_parameters":{"id":"96b668d0-a1b6-11ed-afdf-d39a49596974"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
actions | array | Output field: actions |
actions.connector_type_id | string | Unique identifier |
actions.frequency | object | Output field: actions.frequency |
actions.frequency.notify_when | string | Output field: actions.frequency.notify_when |
actions.frequency.summary | boolean | Output field: actions.frequency.summary |
actions.frequency.throttle | object | Output field: actions.frequency.throttle |
actions.group | string | Output field: actions.group |
actions.id | string | Unique identifier |
actions.params | object | Output field: actions.params |
actions.params.level | string | Output field: actions.params.level |
actions.params.message | string | Response message |
actions.uuid | string | Unique identifier |
api_key_created_by_user | boolean | Output field: api_key_created_by_user |
api_key_owner | string | Output field: api_key_owner |
consumer | string | Output field: consumer |
created_at | string | Output field: created_at |
created_by | string | Output field: created_by |
enabled | boolean | Output field: enabled |
execution_status | object | Status value |
execution_status.last_duration | number | Status value |
execution_status.last_execution_date | string | Status value |
execution_status.status | string | Status value |
id | string | Unique identifier |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"actions":[{}],"api_key_created_by_user":false,"api_key_owner":"elastic","consumer":"alerts","created_at":"2024-03-26T23:13:20.985Z","created_by":"elastic","enabled":true,"execution_status":{"last_duration":52,"last_execution_date":"2024-03-26T23:22:51.390Z","status":"ok"},"id":"ac4e6b90-6be7-11eb-ba0d-9b1c1f912d74","last_run":{"alerts_count":{},"outcome":"succeeded","outcome_msg":null,"warning":null},"mute_all":false,"muted_ale...
Update Cases
Update existing cases in Elastic Kibana V9 using the provided JSON body containing case details.
Endpoint
- URL: /api/cases
- Method: PATCH
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
cases | array | Optional | Parameter for Update Cases |
cases.assignee | array | Optional | An array containing users that are assigned to the case. |
cases.category | string | Optional | A word or phrase that categorizes the case. |
cases.closeReason | string | Optional | The close reason to sync to attached alerts when closing the case. |
cases.connector | object | Optional | Defines properties for connectors when type is .cases-webhook. |
cases.customFields | array | Optional | Custom field values for a case. Any optional custom fields that are not specified in the request are set to null. |
cases.description | string | Optional | The description for the case. |
cases.id | string | Required | The identifier for the case. |
cases.settings | object | Optional | An object that contains the case settings. |
cases.severity | string | Optional | The severity of the case. |
cases.status | string | Optional | The status of the case. |
cases.tags | array | Optional | The words and phrases that help categorize cases. It can be an empty array. |
cases.title | string | Optional | Parameter for Update Cases |
cases.version | string | Required | Parameter for Update Cases |
Input Example
{"json_body":{"cases":[{"assignee":[{}],"category":"cases","closeReason":"false_positive","connector":{},"customFields":[{}],"description":"A case description.","id":"a18b38a0-71b0-11ea-a0b2-c51ea50a58e2","settings":{},"severity":"high","status":"open","tags":["tag-1"],"title":"Case title 1","version":"WzIzLDFd"}]}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":[{"assignees":[],"category":null,"closed_at":null,"closed_by":null,"comments":[],"connector":{},"created_at":"2023-10-13T09:16:17.416Z","created_by":{},"customFields":[],"description":"A case description.","duration":null,"external_service":{},"id":"66b9aa00-94fa-11ea-9f74-e7e108796192","observables":[],"owner":"cases"}]}
Response Headers
Header | Description | Example |
|---|---|---|
Content-Type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Thu, 01 Jan 2024 00:00:00 GMT |