How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Elastic Stack (ELK Stack) Security Entity Analytics API

Use the Security entity analytics APIs to manage entity analytics and risk scoring, including asset criticality, privileged user monitoring, and entity engines.

Elastic Stack (ELK Stack) Security Entity Analytics API is one of 132 APIs that Elastic Stack (ELK Stack) publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Security Entity Analytics API. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.

This API exposes 29 operations across 25 paths, and defines 42 schemas. It is described by OpenAPI 3.2.0.

Requests are made against a single base URL, https://{kibana_url}.

29 operations 25 paths 42 schemas 4 DELETE9 GET1 PATCH13 POST2 PUT

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
Base URL
https://{elasticsearch_endpoint}
Authentication
API Key, HTTP Basic
Contact
Kibana Team
Resource Areas
1

Authentication & Security 2

Elastic Stack (ELK Stack) Security Entity Analytics API declares 2 security schemes for authenticating requests. An API key is passed in the header as Authorization (apiKeyAuth). It accepts HTTP basic authentication (basicAuth). By default, every request must be authenticated.

  • apiKeyAuth — These APIs use key-based authentication. You must create an API key and use the encoded value in the request header. For example: Authorization: ApiKey base64A…

Paths & Operations 29

Across 25 paths, the API surfaces 29 operations — 4 DELETE, 9 GET, 1 PATCH, 13 POST, 2 PUT. Each is listed below with its method, path, parameters, and response codes.

Security Entity Analytics API 29

Use the Security entity analytics APIs to manage entity analytics and risk scoring, including asset criticality, privileged user monitoring, and entity engines.

DELETE
/api/asset_criticalitydeprecated
Delete an asset criticality record
DeleteAssetCriticalityRecord 3 params → 200400
GET
/api/asset_criticalitydeprecated
Get an asset criticality record
GetAssetCriticalityRecord 2 params → 200400404
POST
/api/asset_criticalitydeprecated
Upsert an asset criticality record
CreateAssetCriticalityRecord body → 200400
POST
/api/asset_criticality/bulkdeprecated
Bulk upsert asset criticality records
BulkUpsertAssetCriticalityRecords body → 200413
GET
/api/asset_criticality/listdeprecated
List asset criticality records
FindAssetCriticalityRecords 5 params → 200
DELETE
/api/entity_analytics/monitoring/engine/deletedeprecated
Delete the Privilege Monitoring Engine
DeleteMonitoringEngine 1 param → 200
POST
/api/entity_analytics/monitoring/engine/disabledeprecated
Disable the Privilege Monitoring Engine
DisableMonitoringEngine → 200
POST
/api/entity_analytics/monitoring/engine/initdeprecated
Initialize the Privilege Monitoring Engine
InitMonitoringEngine → 200500
POST
/api/entity_analytics/monitoring/engine/schedule_nowdeprecated
Schedule the Privilege Monitoring Engine
ScheduleMonitoringEngine → 200409
GET
/api/entity_analytics/monitoring/privileges/healthdeprecated
Health check on Privilege Monitoring
PrivMonHealth → 200
GET
/api/entity_analytics/monitoring/privileges/privilegesdeprecated
Run a privileges check on Privilege Monitoring
PrivMonPrivileges → 200
POST
/api/entity_analytics/monitoring/usersdeprecated
Create a new monitored user
CreatePrivMonUser body → 200
POST
/api/entity_analytics/monitoring/users/_csvdeprecated
Upsert multiple monitored users via CSV upload
PrivmonBulkUploadUsersCSV body → 200413
DELETE
/api/entity_analytics/monitoring/users/{id}deprecated
Delete a monitored user
DeletePrivMonUser 1 param → 200
PUT
/api/entity_analytics/monitoring/users/{id}deprecated
Update a monitored user
UpdatePrivMonUser 1 param body → 200
GET
/api/entity_analytics/monitoring/users/listdeprecated
List all monitored users
ListPrivMonUsers 1 param → 200
POST
/api/entity_analytics/privileged_user_monitoring/pad/install
Installs the privileged access detection package for the Entity Analytics privileged user monitoring experience
InstallPrivilegedAccessDetectionPackage → 200
GET
/api/entity_analytics/privileged_user_monitoring/pad/status
Gets the status of the privileged access detection package for the Entity Analytics privileged user monitoring experience
GetPrivilegedAccessDetectionPackageStatus → 200
POST
/api/entity_analytics/watchlists
Create a new watchlist
CreateWatchlist body → 200
GET
/api/entity_analytics/watchlists/{id}
Get a watchlist by ID
GetWatchlist 1 param → 200
PUT
/api/entity_analytics/watchlists/{id}
Update an existing watchlist
UpdateWatchlist 1 param body → 200
POST
/api/entity_analytics/watchlists/{watchlist_id}/csv_upload
Upload a CSV file to add entities to a watchlist
UploadWatchlistCsv 1 param body → 200413
POST
/api/entity_analytics/watchlists/{watchlist_id}/entities/assign
Manually assign entities to a watchlist
AssignWatchlistEntities 1 param body → 200
POST
/api/entity_analytics/watchlists/{watchlist_id}/entities/unassign
Manually unassign entities from a watchlist
UnassignWatchlistEntities 1 param body → 200
GET
/api/entity_analytics/watchlists/list
List all watchlists
ListWatchlists → 200
DELETE
/api/risk_score/engine/dangerously_delete_data
Cleanup the Risk Engine
CleanUpRiskEngine → 200400default
PATCH
/api/risk_score/engine/saved_object/configure
Configure the Risk Engine Saved Object
ConfigureRiskEngineSavedObject body → 200400default
POST
/api/risk_score/engine/schedule_now
Run the risk scoring engine
ScheduleRiskEngineNow body → 200400default
GET
/api/risk_score/history
Get risk score history for an entity
GetRiskScoreHistory 6 params → 200400

Schemas 42

The contract defines 42 schemas that model the data the API accepts and returns. The most detailed are Security_Entity_Analytics_API_RiskScoreHistoryEntry (12 properties), Security_Entity_Analytics_API_UpdateableMonitoringEntitySourceProperties (11 properties), Security_Entity_Analytics_API_WatchlistObject (10 properties), Security_Entity_Analytics_API_RiskScoreInput (8 properties). Each schema is shown below with its type and property counts.

Security_Entity_Analytics_API_WatchlistEntityAssignResponseItem
object
3 properties 2 required
Security_Entity_Analytics_API_EntitySourceType
string
Security_Entity_Analytics_API_WatchlistEntityUnassignResponseItem
object
3 properties 2 required
Security_Entity_Analytics_API_Filter
object
1 property
Security_Entity_Analytics_API_MonitoredUserDoc
Security_Entity_Analytics_API_EntityAnalyticsPrivileges
object
6 properties 2 required
Security_Entity_Analytics_API_CreateAssetCriticalityRecord
Security_Entity_Analytics_API_AssetCriticalityBulkUploadErrorItem
object
2 properties 2 required
Security_Entity_Analytics_API_CleanUpRiskEngineErrorResponse
object
2 properties 2 required
Security_Entity_Analytics_API_AssetCriticalityRecordEcsParts
object
5 properties 1 required
Security_Entity_Analytics_API_PrivmonUserCsvUploadStats
object
4 properties 4 required
Security_Entity_Analytics_API_RiskScoreInput
object
A generic representation of a document contributing to a Risk Score.
8 properties 4 required
Security_Entity_Analytics_API_UpdateableMonitoringEntitySourceProperties
object
11 properties
Security_Entity_Analytics_API_PrivilegeMonitoringEngineStatus
string
The status of the Privilege Monitoring Engine
Security_Entity_Analytics_API_MonitoringEntitySourceProperties
Security_Entity_Analytics_API_AssetCriticalityLevel
string
The criticality level of the asset.
Security_Entity_Analytics_API_RiskEngineScheduleNowResponse
object
1 property
Security_Entity_Analytics_API_AssetCriticalityRecord
Security_Entity_Analytics_API_IdentifierType
string
Security_Entity_Analytics_API_WatchlistObject
object
10 properties 3 required
Security_Entity_Analytics_API_EntityAnalyticsPrivilegesDetail
object
2 properties 1 required
Security_Entity_Analytics_API_MonitoringEntitySource
Security_Entity_Analytics_API_RiskScoreModifier
object
A modifier that was applied to the risk score calculation.
5 properties 2 required
Security_Entity_Analytics_API_Matcher
object
2 properties 2 required
Security_Entity_Analytics_API_MonitoredUserUpdateDoc
object
4 properties
Security_Entity_Analytics_API_MonitoringLabel
object
3 properties 3 required
Security_Entity_Analytics_API_WatchlistCsvUploadResponseItem
object
3 properties 2 required
Security_Entity_Analytics_API_AssetCriticalityLevelsForBulkUpload
string
The criticality level of the asset for bulk upload. The value unassigned is used to indicate that the criticality level is not assigned and is only used for bu…
Security_Entity_Analytics_API_EntityRiskLevels
string
Security_Entity_Analytics_API_AssetCriticalityRecordIdParts
object
2 properties 2 required
Security_Entity_Analytics_API_TaskManagerUnavailableResponse
object
Task manager is unavailable
2 properties 2 required
Security_Entity_Analytics_API_RiskScoreHistoryEntry
object
12 properties 3 required
Security_Entity_Analytics_API_DateRange
object
Defines the lookback period for filtering source data by timestamp.
2 properties 2 required
Security_Entity_Analytics_API_RiskScoreHistoryResponse
object
4 properties 4 required
Security_Entity_Analytics_API_MonitoringEngineDescriptor
object
2 properties 1 required
Security_Entity_Analytics_API_AssetCriticalityBulkUploadStats
object
3 properties 3 required
Security_Entity_Analytics_API_ConfigureRiskEngineSavedObjectErrorResponse
object
2 properties 2 required
Security_Entity_Analytics_API_UserName
object
2 properties
Security_Entity_Analytics_API_PrivmonUserCsvUploadErrorItem
object
3 properties 3 required
Security_Entity_Analytics_API_Integrations
object
2 properties
Security_Entity_Analytics_API_IdField
string
Security_Entity_Analytics_API_RiskEngineScheduleNowErrorResponse
object
2 properties 2 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

elk-stack-security-entity-analytics-api-api-openapi.yml Raw ↑

Other APIs Elastic Stack (ELK Stack) publishes across the network.

Elastic Cloud API
Elastic Stack (ELK Stack) Accounts API
Elastic Stack (ELK Stack) Actions API
Elastic Stack (ELK Stack) agent builder API
Elastic Stack (ELK Stack) Alerting API
Elastic Stack (ELK Stack) Alerting V2 API
Elastic Stack (ELK Stack) Analytics API
Elastic Stack (ELK Stack) APM agent configuration API
Elastic Stack (ELK Stack) APM agent keys API
Elastic Stack (ELK Stack) APM annotations API
Elastic Stack (ELK Stack) APM server schema API
Elastic Stack (ELK Stack) APM sourcemaps API
Where this information came from

This is an independent, third-party profile of Elastic Stack (ELK Stack) Security Entity Analytics API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.