ActionTheHiveUpdated September 2026

How do I open a TheHive case from a workflow?

Short answer: You can create case in TheHive by hand from its own interface, but it won’t repeat itself. On TinyCommand, add the TheHive Create Case action to a workflow, map its 3 inputs from any upstream app, and it runs automatically every time the trigger fires. No code, and a free tier to start.

Create Case in TheHive — start free
Inputs

The fields this action accepts.

Every field can be mapped from an upstream trigger, AI step, table row, or hard-coded literal.

FieldTypeRequiredDescription
Title
title
stringRequiredTitle
Description
description
stringRequiredDescription
Severity
severity
optionsOptionalSeverity. Options: Low, Medium, High, Critical
Sample request
{
"title": "{{trigger.title}}",
"description": "{{trigger.description}}",
"severity": "{{trigger.severity}}"
}
Returns
{
"id": "case_789",
"title": "Investigation",
"severity": 2
}

Use these fields in downstream nodes for routing, logging, or error handling.

Triggered by

Apps that pair well as the trigger for Create Case.

Any of these apps can fire this action as part of a workflow.

FAQ

Questions about Create Case.

What does the Create Case action do in TheHive?
Creates a new investigation case in TheHive with title, description, severity, TLP, and assigned user. Use it to promote a manual report or external ticket into a formal case.
What inputs does Create Case require?
Required: Title, Description. Every input accepts a static value or a variable from any upstream node in your workflow.
Can I use dynamic inputs from earlier workflow nodes?
Yes. Any field on this action can pull values from upstream nodes, whether that's a form response, a trigger payload, an AI output, or a lookup result.
What happens if TheHive returns an error?
The run history shows the failed step with its input and the error message TheHive returned, so you can fix the input and run the workflow again. Automatic retries are built into HTTP steps only, where you can also set your own retry count and delay.
Does Create Case support batch operations?
Run Create Case inside a loop to process each item in an array. TinyCommand does not throttle calls for you, so for large arrays add a Delay step if you need to stay within TheHive's rate limits.
More actions

Other TheHive actions.

Create Case in TheHive — start free