# Aggregating Case Information

**URL:** <https://discuss.elastic.co/t/aggregating-case-information/291836>\
**Category:** SIEM\
**Created:** [December 14, 2021, 4:12pm UTC](https://discuss.elastic.co/t/aggregating-case-information/291836 "2021-12-14T16:12:24Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![bm11100](https://avatars.discourse-cdn.com/v4/letter/b/b3f665/32.png) [@bm11100](https://discuss.elastic.co/u/bm11100)\
**Post date:** [December 14, 2021, 4:12pm UTC](https://discuss.elastic.co/t/aggregating-case-information/291836/1 "2021-12-14T16:12:24Z")

</div>

Hello,

I would like to aggregate case information monthly into certain reports, for example, how many cases were opened in the last month, status, etc..

I know all cases are stored as saved objects, and I was looking in the .kibana index, but having a hard time finding case information there. Is there a particular index in which I can easily aggregate statistics on cases from?

Thanks

---

<div class="post-metadata">

**Author:** ![spong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spong/32/54343_2.png) [@spong](https://discuss.elastic.co/u/spong)\
**Post date:** [January 7, 2022, 8:14pm UTC](https://discuss.elastic.co/t/aggregating-case-information/291836/2 "2022-01-07T20:14:21Z")

</div>

Oh hey there @bm11100! 👋 🙃

As you mentioned, since cases are stored as SO's you'll need to query the `.kibana` directly if you want to perform aggregations on them (since SO aggs aren't supported within Kibana Visualizations yet). Heavy caveat here though that the `.kibana` index is a `system index` and there are future plans to restrict direct access by default, and that modifying anything directly within this index can result in serious problems.

That said, these appear to be all the different `case` related SO types:

> <https://github.com/elastic/kibana/blob/b9c563c41c8ec9d46a95b2c0bf090d0504be44fa/x-pack/plugins/cases/common/constants.ts#L15-L20>

So you should be able to query for each of these in dev tools ala:

```auto
GET .kibana*/_search
{
  "size": 10000,
  "query": {
    "term": {
      "type": {
        "value": "cases"
      }
    }
  }
}

```

and get a response with cases like:

```auto
#! this request accesses system indices: [.kibana_8.1.0_001], but in a future major version, direct access to system indices will be prevented by default
{
  "took": 0,
  "timed_out": false,
  "_shards": {
    "total": 1,
    "successful": 1,
    "skipped": 0,
    "failed": 0
  },
  "hits": {
    "total": {
      "value": 1,
      "relation": "eq"
    },
    "max_score": 6.728628,
    "hits": [
      {
        "_index": ".kibana_8.1.0_001",
        "_id": "cases:2c174a70-6ff4-11ec-97eb-6b110029d6b5",
        "_score": 6.728628,
        "_source": {
          "cases": {
            "type": "individual",
            "title": "New Case From Alert",
            "tags": [
              "case'"
            ],
            "description": "Hope all has been well Brent! :)",
            "settings": {
              "syncAlerts": true
            },
            "owner": "securitySolution",
            "closed_at": null,
            "closed_by": null,
            "created_at": "2022-01-07T19:58:24.408Z",
            "created_by": {
              "username": "elastic",
              "email": null,
              "full_name": null
            },
            "status": "open",
            "updated_at": "2022-01-07T19:58:26.189Z",
            "updated_by": {
              "full_name": null,
              "email": null,
              "username": "elastic"
            },
            "connector": {
              "name": "none",
              "type": ".none",
              "fields": []
            },
            "external_service": null
          },
          "type": "cases",
          "references": [],
          "namespaces": [
            "default"
          ],
          "migrationVersion": {
            "cases": "8.0.0"
          },
          "coreMigrationVersion": "8.1.0",
          "updated_at": "2022-01-07T19:58:26.192Z"
        }
      },
    ]
  }
}

```

Hope this helps! 🙂

Cheers!  
Garrett

---

<div class="post-metadata">

**Author:** ![bm11100](https://avatars.discourse-cdn.com/v4/letter/b/b3f665/32.png) [@bm11100](https://discuss.elastic.co/u/bm11100)\
**Post date:** [January 13, 2022, 10:54pm UTC](https://discuss.elastic.co/t/aggregating-case-information/291836/3 "2022-01-13T22:54:47Z")

</div>

Thank you, Garrett!! That is super helpful.

Is there a way to easily turn said query/variations into a visualization for a dashboard as opposed to just dev tools?

Been having a tough time with all the nested fields going on.

---

<div class="post-metadata">

**Author:** ![spong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spong/32/54343_2.png) [@spong](https://discuss.elastic.co/u/spong)\
**Post date:** [January 14, 2022, 12:05am UTC](https://discuss.elastic.co/t/aggregating-case-information/291836/4 "2022-01-14T00:05:07Z")

</div>

Of course! Happy to help! 🙂

As for leveraging this data within visualization/dashboards, you should be able to create a `Kibana Index Pattern` (now called `Data Views`) within `Stack Management`, and then use that within Lens/Dashboards.

Kibana Index Patterns / Data Views

 ![Data_Views_-_Elastic](https://us1.discourse-cdn.com/elastic/original/3X/1/8/182db46f3cbbfddafff1ffa7375bb973ccd3fc23.png)

Create Data View  
Note: Be sure to click `Allow Hidden & system Indices`, and ensure you select `cases.created_at` as the timestamp

 ![Data_Views_-_Elastic](https://us1.discourse-cdn.com/elastic/original/3X/6/c/6cfc358d2a6943f4c619b0fea936ac71f303b5b9.png)

Now you can use this KIP/Data View in Discover/Dashboards/Lens/etc! 🙂 🎉

 ![Lens_-_Elastic](https://us1.discourse-cdn.com/elastic/original/3X/f/0/f0578328986118c7ec02677c0d87c1089303bc04.png)

And here was the data from within the Security -\> Cases view:

 ![Cases_-_Kibana](https://us1.discourse-cdn.com/elastic/original/3X/0/9/0927228ff003a7a5604f0e29b39723c7987e7ae6.png)

Cheers!  
Garrett

---

<div class="post-metadata">

**Author:** ![bm11100](https://avatars.discourse-cdn.com/v4/letter/b/b3f665/32.png) [@bm11100](https://discuss.elastic.co/u/bm11100)\
**Post date:** [January 14, 2022, 12:20am UTC](https://discuss.elastic.co/t/aggregating-case-information/291836/5 "2022-01-14T00:20:10Z")

</div>

Ahh it was the `cases.created_at` that I did not have! I was using timestamp and could not parse the data in lens. Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 11, 2022, 12:20am UTC](https://discuss.elastic.co/t/aggregating-case-information/291836/6 "2022-02-11T00:20:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
