v53

latestOpenAPI 3.0.3raw.githubusercontent.com2026-08-076771,7565.2 MB
cases

Add a case comment or alert

Spaces method and path for this operation:

<div><span class="operation-verb post">post</span>&nbsp;<span class="operation-path">/s/{space_id}/api/cases/{caseId}/comments</span></div>

Refer to Spaces for more information.

You must have all privileges for the Cases feature in the Management, Observability, or Security section of the Kibana feature privileges, depending on the owner of the case you're creating. NOTE: Each case can have a maximum of 1,000 alerts.

post/api/cases/{caseId}/comments

Path parameters

caseIdstring required
Example:9c235210-6834-11ea-a78c-6ffb38a34414

The identifier for the case. To retrieve case IDs, use the search cases (_find) API. All non-ASCII characters must be URL encoded.

Headers

kbn-xsrfstring required

Cross-site request forgery protection

Request body

OR

Example request

{
  "owner": "cases",
  "rule": {
    "id": "94d80550-aaf4-11ec-985f-97e55adae8b9",
    "name": "security_rule"
  },
  "type": "alert"
}

Response

Indicates a successful call.

categorystring nullable

The case category.

closed_atstring date-time nullable required
created_atstring date-time required
descriptionstring required
durationinteger nullable required

The elapsed time from the creation of the case to its closure (in seconds). If the case has not been closed, the duration is set to null. If the case was closed after less than half a second, the duration is rounded down to zero.

idstring required
incremental_idinteger nullable

A monotonically increasing number assigned to each case, unique per space. This value is generated asynchronously after the case is created and may not be present immediately in the response.

owner'cases' | 'observability' | 'securitySolution' required

The application that owns the cases: Stack Management, Observability, or Elastic Security.

severity'critical' | 'high' | 'low' | 'medium' required

The severity of the case.

status'closed' | 'in-progress' | 'open' required

The status of the case.

tagsstring[] required
titlestring required
total_observablesinteger nullable required

The number of observables attached to the case.

totalAlertsinteger required
totalCommentinteger required
totalEventsinteger

The number of events attached to the case.

updated_atstring date-time nullable required
versionstring required

Example response

{
  "assignees": [
    {
      "uid": "u_0wpfV1MqYDaXzLtRVY-gLMrddKDEmfz51Fszhj7hWC8_0"
    }
  ],
  "closed_by": {
    "profile_uid": "u_J41Oh6L9ki-Vo2tOogS8WRTENzhHurGtRc87NgEAlkc_0",
    "username": "elastic"
  },
  "comments": [
    {
      "alertId": [
        "a6e12ac4-7bce-457b-84f6-d7ce8deb8446"
      ],
      "created_at": "2023-11-06T19:29:38.424Z",
      "created_by": {
        "profile_uid": "u_J41Oh6L9ki-Vo2tOogS8WRTENzhHurGtRc87NgEAlkc_0",
        "username": "elastic"
      },
      "id": "73362370-ab1a-11ec-985f-97e55adae8b9",
      "index": [
        ".internal.alerts-security.alerts-default-000001"
      ],
      "owner": "cases",
      "pushed_by": {
        "profile_uid": "u_J41Oh6L9ki-Vo2tOogS8WRTENzhHurGtRc87NgEAlkc_0",
        "username": "elastic"
      },
      "rule": {
        "id": "94d80550-aaf4-11ec-985f-97e55adae8b9",
        "name": "security_rule"
      },
      "type": "alert",
      "updated_by": {
        "profile_uid": "u_J41Oh6L9ki-Vo2tOogS8WRTENzhHurGtRc87NgEAlkc_0",
        "username": "elastic"
      },
      "version": "WzMwNDgsMV0="
    }
  ],
  "connector": {
    "id": "none",
    "name": "none",
    "type": ".none"
  },
  "created_at": "2022-05-13T09:16:17.416Z",
  "created_by": {
    "profile_uid": "u_J41Oh6L9ki-Vo2tOogS8WRTENzhHurGtRc87NgEAlkc_0",
    "username": "elastic"
  },
  "description": "A case description.",
  "duration": 120,
  "external_service": {
    "pushed_by": {
      "profile_uid": "u_J41Oh6L9ki-Vo2tOogS8WRTENzhHurGtRc87NgEAlkc_0",
      "username": "elastic"
    }
  },
  "id": "66b9aa00-94fa-11ea-9f74-e7e108796192",
  "incremental_id": 1,
  "observables": [
    {
      "createdAt": "2024-11-14T10:00:00.000Z",
      "description": "Source IP",
      "id": "df927ab8-54ed-47d6-be07-9948c255c097",
      "typeKey": "observable-type-ipv4",
      "updatedAt": "2024-11-14T10:00:00.000Z",
      "value": "10.0.0.8"
    }
  ],
  "owner": "cases",
  "settings": {
    "syncAlerts": true
  },
  "tags": [
    "tag-1"
  ],
  "title": "Case title 1",
  "updated_by": {
    "profile_uid": "u_J41Oh6L9ki-Vo2tOogS8WRTENzhHurGtRc87NgEAlkc_0",
    "username": "elastic"
  },
  "version": "WzUzMiwxXQ=="
}