Method: legacySdk.legacyCloseCase

Full name: projects.locations.instances.legacySdk.legacyCloseCase

Closes a specific case and all its constituent alerts. Use this method to formally conclude an investigation, record the final resolution (e.g., true positive, false positive), and free up analyst capacity.

HTTP request


POST https://chronicle.africa-south1.rep.googleapis.com/v1alpha/{instance}/legacySdk:legacyCloseCase

Path parameters

Parameters
instance

string

Required. The CloseCase request. Format: projects/{project}/locations/{location}/instances/{instance}/legacySdk:closeCase

Query parameters

Parameters
format

string

Optional. The format of the field names in the response. Could be snake or camel.

Request body

The request body contains an instance of Struct.

Response body

If successful, the response body is an empty JSON object.

Authorization scopes

Requires one of the following OAuth scopes:

  • https://www.googleapis.com/auth/cloud-platform
  • https://www.googleapis.com/auth/chronicle
  • https://www.googleapis.com/auth/chronicle.readonly

For more information, see the Authentication Overview.

IAM Permissions

Requires the following IAM permission on the instance resource:

  • chronicle.legacySdk.update

For more information, see the IAM documentation.