# Cases API not working on ELK 8.1

**URL:** <https://discuss.elastic.co/t/cases-api-not-working-on-elk-8-1/328066>\
**Category:** Elastic Observability\
**Created:** [March 20, 2023, 11:25am UTC](https://discuss.elastic.co/t/cases-api-not-working-on-elk-8-1/328066 "2023-03-20T11:25:39Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![nitisha](https://avatars.discourse-cdn.com/v4/letter/n/6de8d8/32.png) [@nitisha](https://discuss.elastic.co/u/nitisha)\
**Post date:** [March 20, 2023, 11:25am UTC](https://discuss.elastic.co/t/cases-api-not-working-on-elk-8-1/328066/1 "2023-03-20T11:25:40Z")

</div>

Hi,

I am running ELK stack 8.1 in our production environment and would like to create cases based on the log alerts we're filtering using grok pattern.

As I understood correctly beginning 8.2 version, we have an option to create cases manually from "Stack Management -\> Alerts and Insights -\> Cases", however, until 8.1, the cases can only be created using APIs.

I have referred the following knowledge base article -

> **[Create case | Elastic Security Solution \[8.1\] | Elastic](https://www.elastic.co/guide/en/security/8.1/cases-api-create.html)**

I am assuming in 8.1, once a case is created via API, it would show up under "Observability -\> Cases" as I don't see it under "Stack Management". Please correct me if I am wrong.

Going with the article above, when I tried creating a case via API using POSTMAN, I got the following error -

```auto
{
    "statusCode": 500,
    "error": "Internal Server Error",
    "message": "Unable to create actions client because the Encrypted Saved Objects plugin is missing encryption key. Please set xpack.encryptedSavedObjects.encryptionKey in the kibana.yml or use the bin/kibana-encryption-keys command."
}

```

I would like to know if it is mandatory to have encryption key enabled to utilise this case creation functionality. Additionally, this is a 3-node cluster, if encryption is enabled on the primary node (assuming the other 2 nodes will get synchronised), will it break the existing cluster in any manner?

Thanks,  
Nitish

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 20, 2023, 11:37am UTC](https://discuss.elastic.co/t/cases-api-not-working-on-elk-8-1/328066/2 "2023-03-20T11:37:27Z")

</div>

> [@nitisha](#):
>
> As I understood correctly beginning 8.2 version, we have an option to create cases manually from "Stack Management -\> Alerts and Insights -\> Cases", however, until 8.1, the cases can only be created using APIs.

I don't think this is true, Cases is part of the Security UI and you have the Security UI available in Kibana 8.1 as you can check in the [documentation](https://www.elastic.co/guide/en/security/8.1/es-ui-overview.html).

Not sure if it was made available also in the Stack Management UI, but it is available in the Security UI.

> [@nitisha](#):
>
> I would like to know if it is mandatory to have encryption key enabled to utilise this case creation functionality.

Yes it is, but this is related to the `xpack.encryptedSavedObjects.encryptionKey`, which is a random key used to encrypt settings and rules before storing then in Elasticsearch, it is not related to the encrypted communications between nodes.

> [@nitisha](#):
>
> Additionally, this is a 3-node cluster, if encryption is enabled on the primary node (assuming the other 2 nodes will get synchronised), will it break the existing cluster in any manner?

Can you provide more context? On 8.X security is enabled per default, so the communicaton between your nodes should be already using TLS, unless you explicitly disabled it.

But again, this is different from the error you got, which is related to Kibana.

_Cases_ is a Kibana feature, it runs on Kibana.

---

<div class="post-metadata">

**Author:** ![nitisha](https://avatars.discourse-cdn.com/v4/letter/n/6de8d8/32.png) [@nitisha](https://discuss.elastic.co/u/nitisha)\
**Post date:** [March 20, 2023, 11:49am UTC](https://discuss.elastic.co/t/cases-api-not-working-on-elk-8-1/328066/3 "2023-03-20T11:49:11Z")

</div>

Hi Leandro,

Thanks a lot for the prompt response.

After navigating to "Cases" under "Security" I can see an option to create a case manually. However, I am getting the following error prompts.

 ![495BA1A6-610E-4327-97BF-95A70DD3DBFC_4_5005_c](https://us1.discourse-cdn.com/elastic/original/3X/f/a/fa3c45c7d122440942006e335c60769c9ced1406.jpeg)

Additionally, I haven't explicitly disabled the TLS and is currently enabled.

I am using POST on http://ip:port/api/cases with headers as kbn:xsrf set to true and sending the following json output as body in the same request.

```auto
{
  "description": "Trigger a test alert for any device failure",
  "title": "Test-case",
  "tags": [
    "junos_failure",
    "login_failure"
  ],
  "connector": {
    "id": "none",
    "name": "none",
    "type": ".none",
    "fields": null
  },
  "settings": {
    "syncAlerts": true
  },
  "owner": "securitySolution"
}

```

As you have mentioned that the error which I have received is related to Kibana, if I enable it, will my POST request go through without any errors?

Thanks,  
Nitish

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 20, 2023, 12:07pm UTC](https://discuss.elastic.co/t/cases-api-not-working-on-elk-8-1/328066/4 "2023-03-20T12:07:31Z")

</div>

Did you set `xpack.encryptedSavedObjects.encryptionKey` in `kibana.yml` as described in your error log? This is required, Alerts and Cases will not work without it.

> "Unable to create actions client because the Encrypted Saved Objects plugin is missing encryption key. Please set xpack.encryptedSavedObjects.encryptionKey in the kibana.yml or use the bin/kibana-encryption-keys command."

You can check the [documentation](https://www.elastic.co/guide/en/kibana/master/alert-action-settings-kb.html#general-alert-action-settings) on how to create it.

---

<div class="post-metadata">

**Author:** ![nitisha](https://avatars.discourse-cdn.com/v4/letter/n/6de8d8/32.png) [@nitisha](https://discuss.elastic.co/u/nitisha)\
**Post date:** [March 21, 2023, 5:52am UTC](https://discuss.elastic.co/t/cases-api-not-working-on-elk-8-1/328066/5 "2023-03-21T05:52:27Z")

</div>

Thanks Leandro!

I did the following in order to alleviate the issue:

1. bin/kibana-encryption-keys generate
2. Copied the generated encryption keys to kibana.yml.  
xpack.encryptedSavedObjects.encryptionKey: ######  
xpack.reporting.encryptionKey: #####  
xpack.security.encryptionKey: #####
3. Restarted `ElasticSearch` and `Kibana` service.
