> ## Documentation Index
> Fetch the complete documentation index at: https://docs.blinkops.com/llms.txt
> Use this file to discover all available pages before exploring further.

# SIR Create Case

Create a new security incident response case.

<Note>
  External Documentation

  To learn more, visit the [AWS documentation](https://docs.aws.amazon.com/security-ir/latest/APIReference/API_CreateCase.html).
</Note>

## Basic Parameters

<div className="integrations-table">
  | Parameter                    | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
  | ---------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
  | AWS Region(s)                | A comma-separated list of AWS region(s) where this action will be executed.<br /><br />For example, to execute in US East and Europe, enter `us-east-1,eu-west-1`.<br /><br />Alternatively, you can use the asterisk symbol `*` to run the action in all available AWS Regions.                                                                                                                                                                                                                                  |
  | Client Token                 | A unique identifier (typically a UUID) to ensure request idempotency, preventing duplicate case creation if a request is retried.                                                                                                                                                                                                                                                                                                                                                                                 |
  | Description                  | A detailed description for the case.                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
  | Engagement Type              | The type of engagement for the case.                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
  | Impacted AWS Regions         | A list of AWS regions objects impacted by the security incident. Each entry should specify a `region` identifier (e.g., `us-east-1`).<br /><br />For example:<br /><pre><code>\[<br />  \{<br />    "region": "us-east-1"<br />  },<br />  \{<br />    "region": "eu-south-1"<br />  }<br />]</code></pre>For more information about `Impacted AWS Regions`, refer to [AWS Security Incident Response API documentation](https://docs.aws.amazon.com/security-ir/latest/APIReference/API_ImpactedAwsRegion.html). |
  | Impacted Accounts            | A comma-separated list of accounts impacted by the incident.<br /><br />**Note**: AWS account IDs must always be exactly 12 digits. IDs with fewer than 12 digits must be zero-padded at the beginning. For example, account ID `123123123` (9 digits) should be formatted as `000123123123`.                                                                                                                                                                                                                     |
  | Impacted Services            | A comma-separated list of services impacted by the security incident.                                                                                                                                                                                                                                                                                                                                                                                                                                             |
  | Reported Incident Start Date | The initial start date of the unauthorized activity.                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
  | Resolver Type                | The entity responsible for resolving the case.                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
  | Threat Actor IP Addresses    | A list of suspicious IP addresses associated with unauthorized activity. Each entry must include `ipAddress`.<br /><br />For example:<br /><pre><code>\[<br />  \{<br />    "ipAddress": "192.0.2.1",<br />    "userAgent": "Mozilla/5.0"<br />  }<br />]</code></pre>                                                                                                                                                                                                                                            |
  | Title                        | The title of the case.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
  | Watchers                     | A list of individuals who will receive notifications about case updates. Each entry must include `email` address.<br /><br />For example:<br /><pre><code>\[<br />  \{<br />    "name": "John Doe",<br />    "email": "[john.doe@example.com](mailto:john.doe@example.com)",<br />    "jobTitle": "Security Engineer"<br />  }<br />]</code></pre>**Note**: The maximum number of watchers is 30.                                                                                                                 |
</div>

## Advanced Parameters

<div className="integrations-table">
  | Parameter | Description                                                                                                                                                                       |
  | --------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
  | Tags      | A list of key-value pairs of tags to apply to the case.<br /><br />For example:<br /><pre><code>\{<br />  "Department": "Security",<br />  "Priority": "High"<br />}</code></pre> |
</div>

## Example Output

```json theme={"dark"}
{
	"caseId": "1234567890"
}
```

## Workflow Library Example

[Sir Create Case with Aws and Send Results Via Email](https://library.blinkops.com/workflows/sir-create-case-with-aws-and-send-results-via-email)

<div className="iframe-wrapper">
  <div className="iframe-media">
    <img src="https://mintcdn.com/blinkops-2/ojHYuDeYX5FWuN8a/img/Icons/play-box.svg?fit=max&auto=format&n=ojHYuDeYX5FWuN8a&q=85&s=b8af968e71438a9499c3223c9bd29fb2" alt="Workflow Library" width="16" height="16" data-path="img/Icons/play-box.svg" />

    Preview this Workflow on desktop
  </div>

  <iframe className="iframe" src="https://library.blinkops.com/workflows/sir-create-case-with-aws-and-send-results-via-email/canvas" />
</div>
