Kibana Security Entity Analytics API API is one of 60 APIs that Kibana publishes on the APIs.io network, described by a machine-readable OpenAPI specification.
Tagged areas include Security Entity Analytics API. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and authentication docs.
This API exposes
42 operations
across 35 paths,
and defines 59 schemas.
It is described by OpenAPI 3.0.3.
Requests are made against a single base URL, https://{kibana_url}.
The identity and technical contract details declared by the specification.
Security_Entity_Analytics_API_HostEntity
object
An entity record representing a host, stored in the Entity Store latest index.
5 properties
1 required
Security_Entity_Analytics_API_EntityContainer
object
A wrapper that pairs an entity type with the entity record to upsert.
2 properties
2 required
Security_Entity_Analytics_API_AssetCriticalityRecordEcsParts
object
5 properties
1 required
Security_Entity_Analytics_API_CreateAssetCriticalityRecord
Security_Entity_Analytics_API_Interval
string
Interval in which enrich policy runs. For example, "1h" means the rule runs every hour. Must be less than or equal to half the duration of the lookback period,
Security_Entity_Analytics_API_EntitiesContainer
object
A collection of entities to upsert in bulk.
1 property
1 required
Security_Entity_Analytics_API_ConfigureRiskEngineSavedObjectErrorResponse
object
2 properties
2 required
Security_Entity_Analytics_API_PrivilegeMonitoringEngineStatus
string
The status of the Privilege Monitoring Engine
Security_Entity_Analytics_API_WatchlistObject
object
9 properties
3 required
Security_Entity_Analytics_API_AssetCriticalityBulkUploadStats
object
3 properties
3 required
Security_Entity_Analytics_API_TransformStatsMetadata
object
Statistics from the underlying Elasticsearch transform.
17 properties
15 required
Security_Entity_Analytics_API_EngineComponentResource
string
The type of Elasticsearch or Kibana resource backing an engine component.
Security_Entity_Analytics_API_InspectQuery
object
Debug information about the Elasticsearch query executed.
2 properties
2 required
Security_Entity_Analytics_API_RiskEngineScheduleNowErrorResponse
object
2 properties
2 required
Security_Entity_Analytics_API_EngineDataviewUpdateResult
object
The result of applying data view index changes to a single engine.
2 properties
1 required
Security_Entity_Analytics_API_ServiceEntity
object
An entity record representing a service, stored in the Entity Store latest index.
5 properties
1 required
Security_Entity_Analytics_API_EntityType
string
The type of entity.
Security_Entity_Analytics_API_AssetCriticalityLevelsForBulkUpload
string
The criticality level of the asset for bulk upload. The value unassigned is used to indicate that the criticality level is not assigned and is only used for bu…
Security_Entity_Analytics_API_RiskEngineScheduleNowResponse
object
1 property
Security_Entity_Analytics_API_AssetCriticalityLevel
string
The criticality level of the asset.
Security_Entity_Analytics_API_PrivmonUserCsvUploadErrorItem
object
3 properties
3 required
Security_Entity_Analytics_API_IdField
string
Security_Entity_Analytics_API_EngineDescriptor
object
Describes a single entity engine, including its configuration and current status.
12 properties
4 required
Security_Entity_Analytics_API_EngineComponentStatus
object
Status of an individual Elasticsearch or Kibana resource backing an engine.
6 properties
3 required
Security_Entity_Analytics_API_EntitySourceType
string
Security_Entity_Analytics_API_TaskManagerUnavailableResponse
object
Task manager is unavailable
2 properties
2 required
Security_Entity_Analytics_API_EntityField
object
Core entity fields shared across all entity types. The entity namespace is a root-level field in the Entity Store latest index.
11 properties
1 required
Security_Entity_Analytics_API_CleanUpRiskEngineErrorResponse
object
2 properties
2 required
Security_Entity_Analytics_API_AssetCriticalityBulkUploadErrorItem
object
2 properties
2 required
Security_Entity_Analytics_API_StoreStatus
string
The overall operational status of the Entity Store.
Security_Entity_Analytics_API_AssetCriticalityRecordIdParts
object
2 properties
2 required
Security_Entity_Analytics_API_UserEntity
object
An entity record representing a user, stored in the Entity Store latest index.
5 properties
1 required
Security_Entity_Analytics_API_WatchlistEntityAssignResponseItem
object
3 properties
2 required
Security_Entity_Analytics_API_EngineStatus
string
The current operational status of an entity engine.
Security_Entity_Analytics_API_EntityRiskLevels
string
Security_Entity_Analytics_API_EngineMetadata
object
Internal metadata attached to an entity by the engine that produced it.
1 property
1 required
Security_Entity_Analytics_API_EntityAnalyticsPrivileges
object
4 properties
2 required
Security_Entity_Analytics_API_RiskScoreInput
object
A generic representation of a document contributing to a Risk Score.
8 properties
4 required
Security_Entity_Analytics_API_GenericEntity
object
A generic entity record. Maps only the entity and asset namespaces. Add additional field mappings here as needed.
3 properties
1 required
Security_Entity_Analytics_API_UpdateableMonitoringEntitySourceProperties
object
11 properties
Security_Entity_Analytics_API_MonitoringLabel
object
3 properties
3 required
Security_Entity_Analytics_API_Entity
An entity record from the Entity Store. The entity namespace is a root-level field in the latest index, unlike source logs where it is nested under host, user,…
Security_Entity_Analytics_API_AssetCriticalityRecord
Security_Entity_Analytics_API_Filter
object
1 property
Security_Entity_Analytics_API_Integrations
object
2 properties
Security_Entity_Analytics_API_DateRange
object
Defines the lookback period for filtering source data by timestamp.
2 properties
2 required
Security_Entity_Analytics_API_Asset
object
Asset metadata associated with the entity.
9 properties
Security_Entity_Analytics_API_MonitoringEntitySourceProperties
Security_Entity_Analytics_API_Matcher
object
2 properties
2 required
Security_Entity_Analytics_API_WatchlistEntityUnassignResponseItem
object
3 properties
2 required
Security_Entity_Analytics_API_PrivmonUserCsvUploadStats
object
4 properties
4 required
Security_Entity_Analytics_API_EntityRiskScoreRecord
object
18 properties
10 required
Security_Entity_Analytics_API_IndexPattern
string
An additional Elasticsearch index pattern to include as a source for entity data. Merged with the default data view indices when the engine runs.
Security_Entity_Analytics_API_MonitoringEngineDescriptor
object
2 properties
1 required
Security_Entity_Analytics_API_UserName
object
2 properties
Security_Entity_Analytics_API_WatchlistCsvUploadResponseItem
object
3 properties
2 required
Security_Entity_Analytics_API_MonitoringEntitySource
Security_Entity_Analytics_API_MonitoredUserDoc
Security_Entity_Analytics_API_MonitoredUserUpdateDoc
object
4 properties
The full machine-readable OpenAPI contract behind this narrative.
Other APIs Kibana publishes across the network.