Automate Case Management in TheHive with n8n

Save hours managing cybersecurity cases with this n8n workflow that creates, updates, and retrieves cases in TheHive automatically. Perfect for security analysts needing accurate, fast incident tracking.
manualTrigger
theHive
Workflow Identifier: 1420
NODES in Use: Manual Trigger, TheHive
Automate case management with n8n and TheHive

Press CTRL+F5 if the workflow didn't load.

Learn how to Build this Workflow with AI:

What This Automation Does ⚙️

This workflow makes handling security cases in TheHive much faster and less mistake-prone.
It helps you create, update, and check case details automatically without doing these steps by hand.
This saves hours and keeps your incident info accurate and fresh.

The workflow starts with you clicking a button to run it.
It builds a new case with details like title, description, severity, date, owner, and tags.

Then it changes the case severity if needed.
After that, it fetches the latest case details to confirm the update.

You get the updated case info right away.
No more typing errors or forgetting to update.


Who Should Use This Workflow

This workflow is for anyone who manages security incidents in TheHive and wants to stop doing repetitive, manual case updates.
It fits security analysts who want to save time and be sure their cases always show the latest info.


Tools and Services Used

  • n8n: to build and run the automation workflow.
  • TheHive API: to create, update, and get case information.
  • API Key: needed to safely access TheHive platform functions.

Beginner Step-by-Step: How to Use This Workflow in n8n

Import the Workflow

  1. Download the supplied workflow file using the Download button on this page.
  2. Open n8n editor where the workflow runs.
  3. Use Import from File to load the workflow.

Configure Credentials and Settings

  1. Set up your TheHive API credentials under the workflow’s TheHive nodes.
  2. Check any IDs, emails, channels, or tables in the workflow and change them if your setup needs it.

Test and Activate

  1. Manually run the workflow once to make sure it works without errors.
  2. Look for the new case in TheHive and see the updates made.
  3. Turn on the workflow to run whenever you want or connect it to other triggers later.

For users running self-host n8n, the same import and setup applies.


Inputs, Processing, and Outputs

Inputs

  • Manual trigger to start the workflow.

Processing Steps

  • Create a new case in TheHive with set fields like title, severity, and tags.
  • Update the same case’s severity to a higher level.
  • Get the most recent case details by ID.

Output

  • Returns the updated case information instantly after operations.

Edge Cases and Failures

If authentication to TheHive API fails, check the API Key credentials used in n8n.
They might be wrong or expired. Fix by re-entering correct keys in n8n settings.

If update or get nodes can’t find the case ID, the expression to extract the ID might be wrong.
Confirm the ID references {{$node["TheHive"].json["id"]}} exactly as in creation node output.


Customization Ideas ✏️

  • Change severity update rule to other levels or add fields like status or description.
  • Make dates and titles dynamic by using expressions from input data or external sources.
  • Add extra tags to cases reflecting different team needs or incident types.

Summary

✓ Saves hours daily by automating case creation and updates.
✓ Ends errors caused by manual case handling.
✓ Gives real-time updated case info.
✓ Helps faster and more accurate security incident response.


Automate case management with n8n and TheHive

Visit through Desktop to Interact with the Workflow.

Promoted by BULDRR AI

Related Workflows

Automate Twist Channel Creation and Messaging with n8n

This workflow automates creating and updating a channel in Twist and sending a personalized message to specific users. It eliminates manual setup errors and saves time managing Twist communications.

Automate Ideogram Image Generation with Google Sheets & Gmail

This workflow automates graphic design image generation via Ideogram AI, storing image data in Google Sheets and Google Drive, with email alerts via Gmail. It saves designers hours by automating image creation, remixing, review, and record-keeping.

Automate IT Support with Slack and OpenAI in n8n

Streamline IT support by automating Slack message handling using n8n and OpenAI. This workflow handles Slack DMs, filters bots, queries a Confluence knowledge base, and delivers AI-generated responses, improving support efficiency and response time.

Automate Crypto Analysis with CoinMarketCap & n8n AI Agent

Discover how this unique n8n workflow leverages CoinMarketCap’s multi-agent AI to deliver precise, real-time cryptocurrency insights directly via Telegram. Manage crypto data analysis efficiently with automated multi-source API integration.

Automate Gumroad to Beehiiv Subscriber Sync with n8n

Learn how to automatically add new Gumroad sales customers as Beehiiv newsletter subscribers using n8n automation. This workflow saves time by syncing sales data to Google Sheets CRM and notifying your Telegram channel instantly.

Generate On-Brand Blog Articles Using n8n and OpenAI

This workflow automates the creation of on-brand blog articles by analyzing existing company content using n8n and OpenAI. It extracts article structures and brand voice to produce consistent draft articles, saving significant content creation time.
1:1 Free Strategy Session
Your competitors are already automating. Are you still paying for it manually?

Do you want to adopt AI Automation?

Every hour your team does repetitive work, you're burning real money.
While you wait, faster businesses are cutting costs and moving quicker.
AI and automations aren't the future anymore — they're the present.

Book a live 1-on-1 session where we show you exactly which of your daily tasks can be automated — and what it’s costing you not to.