# How can I get the list of Cases from Kibana Security which are updated in the last day?

**URL:** <https://discuss.elastic.co/t/how-can-i-get-the-list-of-cases-from-kibana-security-which-are-updated-in-the-last-day/378639>\
**Category:** Elastic Security\
**Created:** [May 28, 2025, 10:22am UTC](https://discuss.elastic.co/t/how-can-i-get-the-list-of-cases-from-kibana-security-which-are-updated-in-the-last-day/378639 "2025-05-28T10:22:02Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sergie](https://avatars.discourse-cdn.com/v4/letter/s/85e7bf/32.png) [@Sergie](https://discuss.elastic.co/u/Sergie)\
**Post date:** [May 28, 2025, 10:22am UTC](https://discuss.elastic.co/t/how-can-i-get-the-list-of-cases-from-kibana-security-which-are-updated-in-the-last-day/378639/1 "2025-05-28T10:22:02Z")

</div>

Is there an API or a way where I can get the cases built in Kibana Security thing based on last\_updated value from a case.  
basically I want to get a list of cases that have been updated in last 24 hours

I tried using the api GET /api/cases/\_find

> **[Search cases | Kibana API documentation (v9)](https://www.elastic.co/docs/api/doc/kibana/v9/operation/operation-findcasesdefaultspace)**
>
> The Kibana REST APIs enable you to manage resources such as connectors, data views, and saved objects.
> The API calls are stateless.
> Each request that you mak...

but even the from and to parameters listed here works on created\_date field for a case.

Is there a way to achieve it by this API or any other elastic/kibana api , kindy help.

---

<div class="post-metadata">

**Author:** ![Philippe\_Oberti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philippe_oberti/32/118677_2.png) [@Philippe\_Oberti](https://discuss.elastic.co/u/Philippe_Oberti)\
**Post date:** [June 3, 2025, 3:57pm UTC](https://discuss.elastic.co/t/how-can-i-get-the-list-of-cases-from-kibana-security-which-are-updated-in-the-last-day/378639/2 "2025-06-03T15:57:25Z")

</div>

Hey @Sergie 👋

At this time this is not feasible via the API. Using the API you linked in your original question, the only thing you can do is retrieving X number of cases sorted by the `updated_at` field.

This is not exactly what you want...  
To do what you want, we need to update the API to allow retrieving cases within a specific time range.

I'm going to create a ticket and will have a member of the Cases team look at it!
