get_case_observables
Retrieve all observables linked to a specific case. Filter by creation date and sort results for efficient analysis.
Instructions
List all observables associated with a specific Case.
Args: case_id (str): The unique ID or name/number of the Case. sort (str, optional): Field to sort by. Use '-' prefix for descending (e.g., '-_createdAt' or '-_updatedAt'). created_after (str, optional): Filter observables created after this date (ISO 8601 or timestamp in ms). created_before (str, optional): Filter observables created before this date (ISO 8601 or timestamp in ms). limit (int): Maximum number of observables to return. Default is 50.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| sort | No | ||
| limit | No | ||
| case_id | Yes | ||
| created_after | No | ||
| created_before | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |