cases

post/cases

Request body

descriptionstring nullable
entityTypestring nullable
entityValuestring nullable
evidenceobject nullable

Initial evidence payload attached to the case at creation

linkedAlertIdstring nullable
linkedCveFindingIdstring nullable
linkedReportIdstring nullable
prioritystring nullable
sourceIdstring nullable

Identifier of the originating record

sourceTypestring nullable

Origin surface of the case (e.g. report, alert) — used with sourceId to resolve the linked record and seed initial evidence

titlestring required

Response

Created case

createdAtstring required
descriptionstring nullable
entityTypestring nullable
entityValuestring nullable
idstring required
linkedAlertIdstring nullable
linkedCveFindingIdstring nullable
linkedReportIdstring nullable
organizationIdstring nullable
prioritystring required
statusstring required
titlestring required
updatedAtstring required
userIdstring required

Changes