The Case Management Query Action
Parameter | Description |
---|---|
Table Name | Type of Table: Alerts, Attachments, Cases, Custom Table, Observables, Tasks |
Fields | Field Types |
Condition (Optional) | Condition that compares two Case Management table field values. |
Advanced-Limit (Optional) | Query Limit |
Parameter | Description |
---|---|
SQL Query | The SQL Query |
Output Format | Output Format Types: Table, CSV or JSON |
<inserted_table_name>
with the actual table name that is associated with the cases.Name | Display Name |
---|---|
case_id | Case ID |
type | Case Type |
severity | Severity |
name | Name |
summary | Summary |
created_at | Created At |
case_manager | Case Manager |
status | Status |
linked_observables | Linked Observables |
close_reason | Close Reason |
closed_at | Closed At |
closed_by | Closed By |
closed_by_workflow | Closed By Workflow |
collaborators | Collaborators |
created_by | Created By |
linked_alerts | Linked Alerts |
linked_attachments | Linked Attachments |
linked_cases | Linked Cases |
linked_tasks | Linked Tasks |
mitre_attack | Mitre Attack |
response | Response |
sla | SLA |
sla_expiry | SLA Expiry |
case_tags | Tags |
created_at | Created At |
vendors | Vendors |
Name | Display Name |
---|---|
created_by | Created By |
content | Content |
enrichment_data | Enrichment Data |
updated_at | Updated At |
case_ids | Linked Cases |
attachment_ids | Linked Attachments |
task_ids | Linked Tasks |
name | Name |
type | Observable Type |
description | Description |
verdict | Verdict |
alert_ids | Linked Alerts |
id | ID |
updated_by | Updated By |
observable_id | Observable ID |
auto_id | Observable Number |
observable_ids | Linked Observables |
Name | Display Name |
---|---|
processed | Processed |
id | ID |
updated_at | Updated At |
created_by | Created By |
updated_by | Updated By |
observable_ids | Linked Observables |
template_exists | Template Exists |
severity | Severity |
response | Response |
alert_id | Alert ID |
case_ids | Linked Cases |
type | Alert Type |
name | Name |
vendor | Vendor |
event | Event |
description | Description |
attachment_ids | Linked Attachments |
Name | Display Name |
---|---|
updated_at | Updated At |
created_by | Created By |
updated_by | Updated By |
id | ID |
ioc_ids | Linked IOCs |
alert_ids | Linked Alerts |
attachment | Attachment |
attachment_id | Attachment ID |
case_ids | Linked Cases |
description | Description |
name | Name |
response | Response |
task_ids | Linked Tasks |
type | Attachment Type |
menu | Menu |
observable_ids | Linked Observables |
created_at | Created At |
Name | Display Name |
---|---|
updated_at | Updated At |
id | ID |
created_by | Created By |
updated_by | Updated By |
created_at | Created At |
observable_ids | Linked Observables |
is_blocking | Block closing case until done |
description | Description |
closed_at | Closed At |
case_ids | Linked Cases |
task_id | Task ID |
due_date | Due date |
task_ids | Linked Tasks |
name | Name |
status | Status |
alert_ids | Linked Alerts |
priority | Priority |