Method: legacySdk.legacyCreateCase

Full name: projects.locations.instances.legacySdk.legacyCreateCase

Creates a new investigation case. Use this method to programmatically initiate investigations for technical detection events that are not automatically ingested by standard connectors.

HTTP request


POST https://chronicle.africa-south1.rep.googleapis.com/v1alpha/{instance}/legacySdk:legacyCreateCase

Path parameters

Parameters
instance

string

Required. The CreateCase request. Format: projects/{project}/locations/{location}/instances/{instance}/legacySdk:createCase

Query parameters

Parameters
format

string

Optional. The format of the field names in the response. Could be snake or camel.

Request body

The request body contains an instance of Struct.

Response body

If successful, the response body is an empty JSON object.

Authorization scopes

Requires one of the following OAuth scopes:

  • https://www.googleapis.com/auth/cloud-platform
  • https://www.googleapis.com/auth/chronicle
  • https://www.googleapis.com/auth/chronicle.readonly

For more information, see the Authentication Overview.

IAM Permissions

Requires the following IAM permission on the instance resource:

  • chronicle.legacySdk.update

For more information, see the IAM documentation.