The identity and technical contract details declared by the specification.
Security_Exceptions_API_UpdateExceptionListItemEventFilters
Security_Exceptions_API_ExceptionListItemEntryMatchAny
object
4 properties
4 required
Security_Exceptions_API_ExceptionListTags
array
String array containing words and phrases to help categorize exception containers.
Security_Exceptions_API_TrustedDevicesWindowsMacProperties
object
Trusted devices list item properties (Windows + macOS, username not supported).
4 properties
1 required
Security_Exceptions_API_UpdateExceptionListItemTrustedAppsLinux
Security_Exceptions_API_PlatformErrorResponse
object
3 properties
3 required
Security_Exceptions_API_CreateExceptionListItemTrustedAppsMac
Security_Exceptions_API_CreateRuleExceptionListItemProps
object
11 properties
4 required
Security_Exceptions_API_BlocklistWindowsCodeSignatureEntry
object
3 properties
3 required
Security_Exceptions_API_CreateExceptionListItemTrustedDevicesWindows
Security_Exceptions_API_UpdateExceptionListItemCommentArray
array
Security_Exceptions_API_UUID
string
A universally unique identifier
Security_Exceptions_API_ExceptionNamespaceType
string
Determines whether the exception container is available in all Kibana spaces or just the space in which it is created, where: - single: Only available in the K…
Security_Exceptions_API_CreateExceptionListItemTrustedAppsLinux
Security_Exceptions_API_ExceptionListItemEntryOperator
string
Security_Exceptions_API_UpdateExceptionListItemGeneric
Security_Exceptions_API_ExceptionListItemHumanId
string
Human readable string identifier, e.g. trusted-linux-processes
Security_Exceptions_API_UpdateExceptionListItemBase
object
10 properties
3 required
Security_Exceptions_API_CreateRuleExceptionListItemCommentArray
array
Security_Exceptions_API_ExceptionListItemId
string
Exception's identifier.
Security_Exceptions_API_BlocklistWindowsProperties
object
Blocklist list item properties (Windows, supports code signature).
4 properties
1 required
Security_Exceptions_API_UpdateExceptionListItemTrustedDevicesMac
Security_Exceptions_API_UpdateExceptionListItemHostIsolation
Security_Exceptions_API_CreateExceptionListItemTrustedAppsWindows
Security_Exceptions_API_UpdateExceptionListItemBlocklistLinux
Security_Exceptions_API_ExceptionListItemEntryMatch
object
4 properties
4 required
Security_Exceptions_API_HostIsolationProperties
object
Host isolation exceptions list item properties.
4 properties
1 required
Security_Exceptions_API_ExceptionListItemEntryArray
array
Security_Exceptions_API_ExceptionListOsTypeArray
array
Use this field to specify the operating system. Only enter one value.
Security_Exceptions_API_NonEmptyString
string
A string that does not contain only whitespace characters
Security_Exceptions_API_ExceptionListItemEntryNestedEntryItem
Security_Exceptions_API_UpdateExceptionListItemBlocklistWindows
Security_Exceptions_API_BlocklistHashOrPathEntry
object
4 properties
4 required
Security_Exceptions_API_SiemErrorResponse
object
2 properties
2 required
Security_Exceptions_API_ExceptionListItemEntryMatchWildcard
object
4 properties
4 required
Security_Exceptions_API_ExceptionListOsType
string
Use this field to specify the operating system.
Security_Exceptions_API_UpdateExceptionListItemTrustedDevicesWindowsMac
Security_Exceptions_API_ExceptionListItemMeta
object
Security_Exceptions_API_CreateExceptionListItemCommentArray
array
Security_Exceptions_API_ListType
string
Specifies the Elasticsearch data type of excludes the list container holds. Some common examples: - keyword: Many ECS fields are Elasticsearch keywords - ip: I…
Security_Exceptions_API_TrustedDevicesWindowsProperties
object
Trusted devices list item properties (Windows-only, allows username field).
4 properties
1 required
Security_Exceptions_API_EventFiltersProperties
object
Event filters list item properties.
4 properties
1 required
Security_Exceptions_API_EndpointListProperties
object
Elastic Endpoint exception list item properties.
4 properties
1 required
Security_Exceptions_API_ExceptionListVersion
integer
The document version, automatically increasd on updates.
Security_Exceptions_API_CreateExceptionListItemTrustedDevicesMac
Security_Exceptions_API_ExceptionListDescription
string
Describes the exception list.
Security_Exceptions_API_ExceptionListItemExpireTime
string
The exception item’s expiration date, in ISO format. This field is only available for regular exception items, not endpoint exceptions.
Security_Exceptions_API_CreateExceptionListItemTrustedDevicesWindowsMac
Security_Exceptions_API_ExceptionListName
string
The name of the exception list.
Security_Exceptions_API_ExceptionListItemCommentArray
array
Array of comment fields: - comment (string): Comments about the exception item.
Security_Exceptions_API_TrustedAppsWindowsProperties
object
Trusted applications list item properties (Windows).
4 properties
1 required
Security_Exceptions_API_CreateExceptionListItemBlocklistMac
Security_Exceptions_API_FindExceptionListsFilter
string
Security_Exceptions_API_TrustedAppPathEntry
object
4 properties
4 required
Security_Exceptions_API_CreateExceptionListItemHostIsolation
Security_Exceptions_API_UpdateExceptionListItemComment
object
2 properties
1 required
Security_Exceptions_API_TrustedAppWindowsCodeSignatureEntry
object
3 properties
3 required
Security_Exceptions_API_ExceptionListItemComment
object
6 properties
4 required
Security_Exceptions_API_CreateRuleExceptionListItemComment
object
1 property
1 required
Security_Exceptions_API_ExceptionListItemType
string
Security_Exceptions_API_ExceptionListItemEntry
Security_Exceptions_API_ExceptionListItemEntryList
object
4 properties
4 required
Security_Exceptions_API_UpdateExceptionListItemTrustedAppsMac
Security_Exceptions_API_ExceptionListsImportBulkError
object
4 properties
1 required
Security_Exceptions_API_UpdateExceptionListItemTrustedDevicesWindows
Security_Exceptions_API_CreateExceptionListItemEventFilters
Security_Exceptions_API_CreateExceptionListItemBase
object
8 properties
3 required
Security_Exceptions_API_TrustedDevicesMacProperties
object
Trusted devices list item properties (macOS-only, username not supported).
4 properties
1 required
Security_Exceptions_API_ExceptionListsImportBulkErrorArray
array
Security_Exceptions_API_ExceptionListItemEntryNested
object
3 properties
3 required
Security_Exceptions_API_ExceptionListItemOsTypeArray
array
Security_Exceptions_API_UpdateExceptionListItemEndpointList
Security_Exceptions_API_ExceptionListItem
object
19 properties
14 required
Security_Exceptions_API_ExceptionListItemDescription
string
Describes the exception list.
Security_Exceptions_API_ExceptionListType
string
The type of exception list to be created. Different list types may denote where they can be utilized.
Security_Exceptions_API_ExceptionListItemTags
array
Security_Exceptions_API_UpdateExceptionListItemTrustedAppsWindows
Security_Exceptions_API_ExceptionListHumanId
string
The exception list's human-readable string identifier. For endpoint artifacts, use one of the following values: endpointlist: [Elastic Endpoint exception list]…
Security_Exceptions_API_ExceptionListItemEntryExists
object
3 properties
3 required
Security_Exceptions_API_CreateExceptionListItemComment
object
1 property
1 required
Security_Exceptions_API_TrustedAppHashEntry
object
4 properties
4 required
Security_Exceptions_API_ExceptionListId
string
Exception list's identifier.
Security_Exceptions_API_TrustedAppsMacProperties
object
Trusted applications list item properties (macOS).
4 properties
1 required
Security_Exceptions_API_TrustedAppMacCodeSignatureEntry
object
3 properties
3 required
Security_Exceptions_API_CreateExceptionListItemEndpointList
Security_Exceptions_API_CreateExceptionListItemGeneric
Security_Exceptions_API_ExceptionList
object
17 properties
13 required
Security_Exceptions_API_TrustedAppsLinuxProperties
object
Trusted applications list item properties (Linux).
4 properties
1 required
Security_Exceptions_API_ListId
string
Value list's identifier.
Security_Exceptions_API_BlocklistLinuxProperties
object
Blocklist list item properties (Linux, code signature not supported).
4 properties
1 required
Security_Exceptions_API_EndpointArtifactTags
array
Tags for categorization. Special tags for scope control: "policy:all" - Global artifact (applies to all Elastic Defend policies) "policy: " - Private artifact…
Security_Exceptions_API_UpdateExceptionListItemBlocklistMac
Security_Exceptions_API_CreateExceptionListItemBlocklistLinux
Security_Exceptions_API_CreateExceptionListItemBlocklistWindows
Security_Exceptions_API_ExceptionListMeta
object
Placeholder for metadata about the list container.
Security_Exceptions_API_ExceptionListItemName
string
Exception list name.
Security_Exceptions_API_BlocklistMacProperties
object
Blocklist list item properties (macOS, code signature not supported).
4 properties
1 required
The full machine-readable OpenAPI contract behind this narrative.
Other APIs Kibana publishes across the network.