Spaces method and path for this operation:
Refer to Spaces for more information.
Case settings include external connection details, custom fields, and templates. Connectors are used to interface with external systems. You must create a connector before you can use it in your cases. If you set a default connector, it is automatically selected when you create cases in Kibana. If you use the create case API, however, you must still specify all of the connector details. You must have all privileges for the Cases feature in the Management, Observability, or Security section of the Kibana feature privileges, depending on where you are creating cases.
Body
-
Indicates whether a case is automatically closed when it is pushed to external systems (
close-by-pushing) or not automatically closed (close-by-user).Values are
close-by-pushingorclose-by-user. -
An object that contains the connector configuration.
-
Custom fields case configuration.
At least
0but not more than10elements. -
Indicates whether observables (for example, IPs, hashes, and URLs) are automatically extracted from case comments and events. When omitted, defaults to the owner's default:
truefor Security,falsefor Stack and Observability. For owners that do not support observable extraction (currently Observability), setting this totruehas no effect on case creation; new cases for those owners always usefalse. -
The application that owns the cases: Stack Management, Observability, or Elastic Security.
Values are
cases,observability, orsecuritySolution.
curl \
--request POST 'https://localhost:5601/api/cases/configure' \
--header "Authorization: $API_KEY" \
--header "Content-Type: application/json" \
--header "kbn-xsrf: string" \
--data '{
"closure_type": "close-by-user",
"connector": {
"fields": null,
"id": "5e656730-e1ca-11ec-be9b-9b1838238ee6",
"name": "my-jira-connector",
"type": ".jira"
},
"customFields": [
{
"defaultValue": "My custom field default value.",
"key": "d312efda-ec2b-42ec-9e2c-84981795c581",
"label": "my-text-field",
"type": "text",
"required": false
}
],
"owner": "cases",
"templates": [
{
"caseFields": {
"assignees": [
{
"uid": "u_mGBROF_q5bmFCATbLXAcCwKa0k8JvONAwSruelyKA5E_0"
}
],
"category": "Default-category",
"customFields": [
{
"key": "d312efda-ec2b-42ec-9e2c-84981795c581",
"type": "text",
"value": "A text field value for the template."
}
],
"description": "A default description for cases.",
"tags": [
"Default case tag"
],
"title": "Default case title"
},
"description": "A description of the template.",
"key": "505932fe-ee3a-4960-a661-c781b5acdb05",
"name": "template-1",
"tags": [
"Template tag 1"
]
}
],
"workflowTags": [
"soc-triage"
]
}'
{
"closure_type": "close-by-user",
"connector": {
"fields": null,
"id": "5e656730-e1ca-11ec-be9b-9b1838238ee6",
"name": "my-jira-connector",
"type": ".jira"
},
"customFields": [
{
"defaultValue": "My custom field default value.",
"key": "d312efda-ec2b-42ec-9e2c-84981795c581",
"label": "my-text-field",
"type": "text",
"required": false
}
],
"owner": "cases",
"templates": [
{
"caseFields": {
"assignees": [
{
"uid": "u_mGBROF_q5bmFCATbLXAcCwKa0k8JvONAwSruelyKA5E_0"
}
],
"category": "Default-category",
"customFields": [
{
"key": "d312efda-ec2b-42ec-9e2c-84981795c581",
"type": "text",
"value": "A text field value for the template."
}
],
"description": "A default description for cases.",
"tags": [
"Default case tag"
],
"title": "Default case title"
},
"description": "A description of the template.",
"key": "505932fe-ee3a-4960-a661-c781b5acdb05",
"name": "template-1",
"tags": [
"Template tag 1"
]
}
],
"workflowTags": [
"soc-triage"
]
}
{
"closure_type": "close-by-user",
"connector": {
"fields": null,
"id": "5e656730-e1ca-11ec-be9b-9b1838238ee6",
"name": "my-jira-connector",
"type": ".jira"
},
"created_at": "2024-07-01T17:07:17.767Z",
"created_by": {
"email": "null,",
"full_name": null,
"profile_uid": "u_mGBROF_q5bmFCATbLXAcCwKa0k8JvONAwSruelyKA5E_0",
"username": "elastic"
},
"customFields": [
{
"defaultValue": "My custom field default value.",
"key": "d312efda-ec2b-42ec-9e2c-84981795c581",
"label": "my-text-field",
"type": "text",
"required": false
}
],
"error": null,
"extractObservables": true,
"id": "4a97a440-e1cd-11ec-be9b-9b1838238ee6",
"mappings": [
{
"action_type": "overwrite",
"source": "title",
"target": "summary"
},
{
"action_type": "overwrite",
"source": "description",
"target": "description"
},
{
"action_type": "append",
"source": "comments",
"target": "comments"
},
{
"action_type": "overwrite",
"source": "tags",
"target": "labels"
}
],
"owner": "cases",
"templates": [
{
"caseFields": {
"assignees": [
{
"uid": "u_mGBROF_q5bmFCATbLXAcCwKa0k8JvONAwSruelyKA5E_0"
}
],
"category": "Default-category",
"customFields": [
{
"key": "d312efda-ec2b-42ec-9e2c-84981795c581",
"type": "text",
"value": "A text field value for the template."
}
],
"description": "A default description for cases.",
"tags": [
"Default case tag"
],
"title": "Default case title"
},
"description": "A description of the template.",
"key": "505932fe-ee3a-4960-a661-c781b5acdb05",
"name": "template-1",
"tags": [
"Template tag 1"
]
}
],
"updated_at": null,
"updated_by": null,
"version": "WzIwNzMsMV0=",
"workflowTags": [
"soc-triage"
]
}
{
"error": "Unauthorized",
"message": "Unable to authenticate with the provided credentials.",
"statusCode": 401
}