Automate Case Management in TheHive with n8n

Save hours managing cybersecurity cases with this n8n workflow that creates, updates, and retrieves cases in TheHive automatically. Perfect for security analysts needing accurate, fast incident tracking.
manualTrigger
theHive
Workflow Identifier: 1420
NODES in Use: Manual Trigger, TheHive

Press CTRL+F5 if the workflow didn't load.

Learn how to Build this Workflow with AI:

Visit through Desktop for Best experience

What This Automation Does ⚙️

This workflow makes handling security cases in TheHive much faster and less mistake-prone.
It helps you create, update, and check case details automatically without doing these steps by hand.
This saves hours and keeps your incident info accurate and fresh.

The workflow starts with you clicking a button to run it.
It builds a new case with details like title, description, severity, date, owner, and tags.

Then it changes the case severity if needed.
After that, it fetches the latest case details to confirm the update.

You get the updated case info right away.
No more typing errors or forgetting to update.


Who Should Use This Workflow

This workflow is for anyone who manages security incidents in TheHive and wants to stop doing repetitive, manual case updates.
It fits security analysts who want to save time and be sure their cases always show the latest info.


Tools and Services Used

  • n8n: to build and run the automation workflow.
  • TheHive API: to create, update, and get case information.
  • API Key: needed to safely access TheHive platform functions.

Beginner Step-by-Step: How to Use This Workflow in n8n

Import the Workflow

  1. Download the supplied workflow file using the Download button on this page.
  2. Open n8n editor where the workflow runs.
  3. Use Import from File to load the workflow.

Configure Credentials and Settings

  1. Set up your TheHive API credentials under the workflow’s TheHive nodes.
  2. Check any IDs, emails, channels, or tables in the workflow and change them if your setup needs it.

Test and Activate

  1. Manually run the workflow once to make sure it works without errors.
  2. Look for the new case in TheHive and see the updates made.
  3. Turn on the workflow to run whenever you want or connect it to other triggers later.

For users running self-host n8n, the same import and setup applies.


Inputs, Processing, and Outputs

Inputs

  • Manual trigger to start the workflow.

Processing Steps

  • Create a new case in TheHive with set fields like title, severity, and tags.
  • Update the same case’s severity to a higher level.
  • Get the most recent case details by ID.

Output

  • Returns the updated case information instantly after operations.

Edge Cases and Failures

If authentication to TheHive API fails, check the API Key credentials used in n8n.
They might be wrong or expired. Fix by re-entering correct keys in n8n settings.

If update or get nodes can’t find the case ID, the expression to extract the ID might be wrong.
Confirm the ID references {{$node["TheHive"].json["id"]}} exactly as in creation node output.


Customization Ideas ✏️

  • Change severity update rule to other levels or add fields like status or description.
  • Make dates and titles dynamic by using expressions from input data or external sources.
  • Add extra tags to cases reflecting different team needs or incident types.

Summary

✓ Saves hours daily by automating case creation and updates.
✓ Ends errors caused by manual case handling.
✓ Gives real-time updated case info.
✓ Helps faster and more accurate security incident response.


Promoted by BULDRR AI

Related Workflows

Automate Viral UGC Video Creation Using n8n + Degaus (Beginner-Friendly Guide)

Learn how to automate viral UGC video creation using n8n, AI prompts, and Degaus. This beginner-friendly guide shows how to import, configure, and run the workflow without technical complexity.
Form Trigger
Google Sheets
Gmail
+37
Free

AI SEO Blog Writer Automation Workflows in n8n

A complete beginner guide to building an AI SEO blog writer automation using n8n.
AI Agent
Google Sheets
httpRequest
+5
Free

Automate CrowdStrike Alerts with VirusTotal, Jira & Slack

This workflow automates processing of CrowdStrike detections by enriching threat data via VirusTotal, creating Jira tickets for incident tracking, and notifying teams on Slack for quick response. Save hours daily by transforming complex threat data into actionable alerts effortlessly.
scheduleTrigger
httpRequest
jira
+5
Free

Automate Telegram Invoices to Notion with AI Summaries & Reports

Save hours on financial tracking by automating invoice extraction from Telegram photos to Notion using Google Gemini AI. This workflow extracts data, records transactions, and generates detailed spending reports with charts sent on schedule via Telegram.
lmChatGoogleGemini
telegramTrigger
notion
+9
Free

Automate Email Replies with n8n and AI-Powered Summarization

Save hours managing your inbox with this n8n workflow that uses IMAP email triggers, AI summarization, and vector search to draft concise replies requiring minimal review. Automate business email processing efficiently with AI guidance and Gmail integration.
emailReadImap
vectorStoreQdrant
emailSend
+12
Free

Automate Email Campaigns Using n8n with Gmail & Google Sheets

This n8n workflow automates personalized email outreach campaigns by integrating Gmail and Google Sheets, saving hours of manual follow-up work and reducing errors in email sequences. It ensures timely follow-ups based on previous email interactions, optimizing communication efficiency.
googleSheets
gmail
code
+5
Free