Every incident response team works against the clock. Analysts have response-time targets to hit, MSSPs juggle deadlines across multiple clients and SOC managers need to prove their team met its commitments. Keeping up with that across every alert, case and task isn’t easy.
TheHive 5.8 brings SLA tracking directly into the platform. This release also lets you customize your dashboards further, extends what the global search can reach and reworks the API documentation.
• Track and enforce SLAs natively, with warnings and breach notifications
• Display custom fields and tags in the dashboard’s Table widget
• Search through comments and pages using the global search bar
• Explore the reworked API documentation, with ready-to-use examples
Never miss a deadline again
Picture a SOC analyst going through the alerts queue. Most are routine, but one has been sitting for a while, and its qualification deadline is getting close.
With TheHive 5.8, organization admins can define SLA rules per entity type (alert, case or task) using the metrics TheHive already tracks. A rule can combine several targets, each with its own conditions, duration and a warning threshold.
TheHive displays timing for each entity directly in its respective queue, with color-coded status and filter options. When an entity crosses the warning threshold or misses the deadline, TheHive notifies the right person through its existing notification system.
A SOC manager can check at a glance whether the team is meeting its response deadlines and get pinged when one is at risk. MSSPs can set different SLA rules per client’s organization, matching each contract’s response times. It will also help incident response teams demonstrate measurable response times to regulators and auditors.
Learn how to define your own SLA rules and notifications
Click on the “Expand” button to zoom:
Your custom fields, now on the dashboard
The Table widget in Dashboards is useful for listing ongoing critical alerts or cases using built-in fields. For many teams, though, what matters most sits in custom fields or tags.
TheHive 5.8 lets you bring that information into the table. For example, an MSSP manager can now set up a custom field recording the client impacted by each alert, then build a dashboard showing the 10 most critical ongoing incidents alongside each client.
Comments and pages join Global Search
TheHive introduced Global Search in 5.6, letting you search across your instance from a single bar. In TheHive 5.8, we’re extending its scope to comments and pages in your knowledge base or cases.
That detail an analyst left in a comment three weeks ago, or the playbook step documented in a knowledge base page, is now just as easy to find as any other entity.
We’ve reworked the API documentation so developers can find what they need faster.
The “Get Started” section is clearer and the Query section now details the operations and extra data available for each entity. Endpoint and parameter descriptions are more complete, with default values and enums where available. We’ve also added concrete examples throughout, including Python and curl snippets you can use as-is. This will also help developers using LLMs to build API requests and integrations for TheHive.
This is a documentation-only update: the API itself, its endpoints, parameters and behavior remain unchanged. Existing integrations keep working.
TheHive 5.8 includes even more: check the full release notes for the details!
Give it a try, and tell us what you think through our contact page!
Not using TheHive yet?
Let's talk about how our platform can improve your incident response