Spaces method and path for this operation:
Refer to Spaces for more information.
Create a new entity record in the Entity Store for the specified entity type.
[Required authorization] Route required privileges: securitySolution.
-
The time the entity record was last updated.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
Additional properties are NOT allowed.
Hide asset attributes Show asset attributes object
-
Business unit the asset belongs to.
-
The criticality level assigned to this asset.
Values are
low_impact,medium_impact,high_impact, orextreme_impact. -
Deployment environment (for example, production, staging).
-
Unique identifier for the asset.
-
Model name or number.
-
Human-readable asset name.
-
The owner of the asset.
-
Serial number of the asset.
-
Vendor or manufacturer.
-
-
Additional properties are NOT allowed.
Hide entity attributes Show entity attributes object
-
Boolean flags describing characteristics of the entity.
Additional properties are NOT allowed.
Hide attributes attributes Show attributes attributes object
-
Whether the entity is classified as an asset.
-
Known redirect URIs or URLs (e.g. OAuth application callbacks).
-
Whether the entity is managed (for example, via a directory service).
-
Whether multi-factor authentication is enabled for the entity.
-
OAuth consent restriction (e.g. admin_only, verified_only, unrestricted).
-
Action-level permissions granted to this entity (not roles or groups).
-
Storage tier or class assigned to a storage resource (e.g. hot, warm, cold, standard, archive).
-
Watchlist identifiers the entity belongs to (v2).
-
-
Behavioral signals observed for the entity.
Additional properties are NOT allowed.
-
Identifies which engine created this entity (for example, logs_extraction or risk_score_maintainer).
-
Additional properties are NOT allowed.
-
Unique identifier for this entity.
-
Timestamps tracking the entity lifecycle.
Additional properties are NOT allowed.
Hide lifecycle attributes Show lifecycle attributes object
-
When the entity was first observed.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
When the entity last generated activity.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
When the entity was last observed.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$.
-
-
Human-readable name of the entity.
-
Connections between this entity and other entities.
Additional properties are NOT allowed.
Hide relationships attributes Show relationships attributes object
-
Entities this entity accesses frequently.
Additional properties are NOT allowed.
Hide accesses_frequently attributes Show accesses_frequently attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity accesses infrequently.
Additional properties are NOT allowed.
Hide accesses_infrequently attributes Show accesses_infrequently attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity administers (for example, a user who is an admin of a service).
Additional properties are NOT allowed.
Hide administers attributes Show administers attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity communicates with.
Additional properties are NOT allowed.
Hide communicates_with attributes Show communicates_with attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity depends on.
Additional properties are NOT allowed.
Hide depends_on attributes Show depends_on attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities owned by this entity.
Additional properties are NOT allowed.
Hide owns attributes Show owns attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities inferred to be owned by this entity.
Additional properties are NOT allowed.
Hide owns_inferred attributes Show owns_inferred attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Resolution metadata linking this entity to another.
Additional properties are NOT allowed.
Hide resolution attributes Show resolution attributes object
-
entity.id of the entity this one resolves to
-
Aggregated risk score for the resolution group.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Lexical description of the resolution group's aggregated risk.
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the resolution group's aggregated risk score.
-
The normalized numeric value of the resolution group's aggregated risk score.
Minimum value is
0, maximum value is100.
-
-
-
Entities supervised by this entity.
Additional properties are NOT allowed.
Hide supervises attributes Show supervises attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
-
Risk scoring information for the entity.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Lexical description of the entity's risk.
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100.
-
-
Schema version of the entity record.
-
Sources that produced this entity record.
-
Optional sub-type classification for the entity.
-
The entity type.
-
URL associated with the entity.
-
-
Additional properties are NOT allowed.
Hide event attribute Show event attribute object
-
When the event was ingested into Elasticsearch.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$.
-
-
Custom key-value labels attached to the entity.
Additional properties are allowed.
-
Tags attached to the entity.
-
Elastic Common Schema (ECS) user fields collected on the entity.
Additional properties are NOT allowed.
Hide user attributes Show user attributes object
-
Observed user domains.
-
Observed email addresses.
-
Observed full names of the user.
-
Observed user hashes.
-
Observed user identifiers.
-
Primary user name.
-
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Lexical description of the entity's risk.
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score.
Minimum value is
0, maximum value is100.
-
-
Observed roles assigned to the user.
-
-
The time the entity record was last updated.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
Additional properties are NOT allowed.
Hide asset attributes Show asset attributes object
-
Business unit the asset belongs to.
-
The criticality level assigned to this asset.
Values are
low_impact,medium_impact,high_impact, orextreme_impact. -
Deployment environment (for example, production, staging).
-
Unique identifier for the asset.
-
Model name or number.
-
Human-readable asset name.
-
The owner of the asset.
-
Serial number of the asset.
-
Vendor or manufacturer.
-
-
Additional properties are NOT allowed.
Hide entity attributes Show entity attributes object
-
Boolean flags describing characteristics of the entity.
Additional properties are NOT allowed.
Hide attributes attributes Show attributes attributes object
-
Whether the entity is classified as an asset.
-
Known redirect URIs or URLs (e.g. OAuth application callbacks).
-
Whether the entity is managed (for example, via a directory service).
-
Whether multi-factor authentication is enabled for the entity.
-
OAuth consent restriction (e.g. admin_only, verified_only, unrestricted).
-
Action-level permissions granted to this entity (not roles or groups).
-
Storage tier or class assigned to a storage resource (e.g. hot, warm, cold, standard, archive).
-
Watchlist identifiers the entity belongs to (v2).
-
-
Behavioral signals observed for the entity.
Additional properties are NOT allowed.
-
Identifies which engine created this entity (for example, logs_extraction or risk_score_maintainer).
-
Additional properties are NOT allowed.
-
Unique identifier for this entity.
-
Timestamps tracking the entity lifecycle.
Additional properties are NOT allowed.
Hide lifecycle attributes Show lifecycle attributes object
-
When the entity was first observed.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
When the entity last generated activity.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
When the entity was last observed.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$.
-
-
Human-readable name of the entity.
-
Connections between this entity and other entities.
Additional properties are NOT allowed.
Hide relationships attributes Show relationships attributes object
-
Entities this entity accesses frequently.
Additional properties are NOT allowed.
Hide accesses_frequently attributes Show accesses_frequently attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity accesses infrequently.
Additional properties are NOT allowed.
Hide accesses_infrequently attributes Show accesses_infrequently attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity administers (for example, a user who is an admin of a service).
Additional properties are NOT allowed.
Hide administers attributes Show administers attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity communicates with.
Additional properties are NOT allowed.
Hide communicates_with attributes Show communicates_with attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity depends on.
Additional properties are NOT allowed.
Hide depends_on attributes Show depends_on attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities owned by this entity.
Additional properties are NOT allowed.
Hide owns attributes Show owns attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities inferred to be owned by this entity.
Additional properties are NOT allowed.
Hide owns_inferred attributes Show owns_inferred attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Resolution metadata linking this entity to another.
Additional properties are NOT allowed.
Hide resolution attributes Show resolution attributes object
-
entity.id of the entity this one resolves to
-
Aggregated risk score for the resolution group.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Lexical description of the resolution group's aggregated risk.
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the resolution group's aggregated risk score.
-
The normalized numeric value of the resolution group's aggregated risk score.
Minimum value is
0, maximum value is100.
-
-
-
Entities supervised by this entity.
Additional properties are NOT allowed.
Hide supervises attributes Show supervises attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
-
Risk scoring information for the entity.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Lexical description of the entity's risk.
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100.
-
-
Schema version of the entity record.
-
Sources that produced this entity record.
-
Optional sub-type classification for the entity.
-
The entity type.
-
URL associated with the entity.
-
-
Additional properties are NOT allowed.
Hide event attribute Show event attribute object
-
When the event was ingested into Elasticsearch.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$.
-
-
Elastic Common Schema (ECS) host fields collected on the entity.
Additional properties are NOT allowed.
Hide host attributes Show host attributes object
-
Observed CPU architectures.
-
Observed host domains.
-
Observed hostnames.
-
Observed host identifiers.
-
Observed IP addresses.
-
Observed MAC addresses.
-
Primary host name.
-
Elastic Common Schema (ECS) host.os fields collected on the entity latest index (v2).
Additional properties are NOT allowed.
Hide os attributes Show os attributes object
-
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Lexical description of the entity's risk.
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score.
Minimum value is
0, maximum value is100.
-
-
Observed host types.
-
-
Custom key-value labels attached to the entity.
Additional properties are allowed.
-
Tags attached to the entity.
-
The time the entity record was last updated.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
Additional properties are NOT allowed.
Hide asset attributes Show asset attributes object
-
Business unit the asset belongs to.
-
The criticality level assigned to this asset.
Values are
low_impact,medium_impact,high_impact, orextreme_impact. -
Deployment environment (for example, production, staging).
-
Unique identifier for the asset.
-
Model name or number.
-
Human-readable asset name.
-
The owner of the asset.
-
Serial number of the asset.
-
Vendor or manufacturer.
-
-
Additional properties are NOT allowed.
Hide entity attributes Show entity attributes object
-
Boolean flags describing characteristics of the entity.
Additional properties are NOT allowed.
Hide attributes attributes Show attributes attributes object
-
Whether the entity is classified as an asset.
-
Known redirect URIs or URLs (e.g. OAuth application callbacks).
-
Whether the entity is managed (for example, via a directory service).
-
Whether multi-factor authentication is enabled for the entity.
-
OAuth consent restriction (e.g. admin_only, verified_only, unrestricted).
-
Action-level permissions granted to this entity (not roles or groups).
-
Storage tier or class assigned to a storage resource (e.g. hot, warm, cold, standard, archive).
-
Watchlist identifiers the entity belongs to (v2).
-
-
Behavioral signals observed for the entity.
Additional properties are NOT allowed.
-
Identifies which engine created this entity (for example, logs_extraction or risk_score_maintainer).
-
Additional properties are NOT allowed.
-
Unique identifier for this entity.
-
Timestamps tracking the entity lifecycle.
Additional properties are NOT allowed.
Hide lifecycle attributes Show lifecycle attributes object
-
When the entity was first observed.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
When the entity last generated activity.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
When the entity was last observed.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$.
-
-
Human-readable name of the entity.
-
Connections between this entity and other entities.
Additional properties are NOT allowed.
Hide relationships attributes Show relationships attributes object
-
Entities this entity accesses frequently.
Additional properties are NOT allowed.
Hide accesses_frequently attributes Show accesses_frequently attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity accesses infrequently.
Additional properties are NOT allowed.
Hide accesses_infrequently attributes Show accesses_infrequently attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity administers (for example, a user who is an admin of a service).
Additional properties are NOT allowed.
Hide administers attributes Show administers attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity communicates with.
Additional properties are NOT allowed.
Hide communicates_with attributes Show communicates_with attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity depends on.
Additional properties are NOT allowed.
Hide depends_on attributes Show depends_on attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities owned by this entity.
Additional properties are NOT allowed.
Hide owns attributes Show owns attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities inferred to be owned by this entity.
Additional properties are NOT allowed.
Hide owns_inferred attributes Show owns_inferred attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Resolution metadata linking this entity to another.
Additional properties are NOT allowed.
Hide resolution attributes Show resolution attributes object
-
entity.id of the entity this one resolves to
-
Aggregated risk score for the resolution group.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Lexical description of the resolution group's aggregated risk.
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the resolution group's aggregated risk score.
-
The normalized numeric value of the resolution group's aggregated risk score.
Minimum value is
0, maximum value is100.
-
-
-
Entities supervised by this entity.
Additional properties are NOT allowed.
Hide supervises attributes Show supervises attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
-
Risk scoring information for the entity.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Lexical description of the entity's risk.
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100.
-
-
Schema version of the entity record.
-
Sources that produced this entity record.
-
Optional sub-type classification for the entity.
-
The entity type.
-
URL associated with the entity.
-
-
Additional properties are NOT allowed.
Hide event attribute Show event attribute object
-
When the event was ingested into Elasticsearch.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$.
-
-
Custom key-value labels attached to the entity.
Additional properties are allowed.
-
Elastic Common Schema (ECS) service fields collected on the entity.
Additional properties are NOT allowed.
Hide service attributes Show service attributes object
-
Service address.
-
Service environment (for example, production, staging).
-
Ephemeral identifier of the service.
-
Unique identifier of the service.
-
Primary service name.
-
Node information for the service.
Additional properties are NOT allowed.
-
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Lexical description of the entity's risk.
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score.
Minimum value is
0, maximum value is100.
-
-
Current state of the service.
-
Service type.
-
Service version.
-
-
Tags attached to the entity.
-
The time the entity record was last updated.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
Additional properties are NOT allowed.
Hide asset attributes Show asset attributes object
-
Business unit the asset belongs to.
-
The criticality level assigned to this asset.
Values are
low_impact,medium_impact,high_impact, orextreme_impact. -
Deployment environment (for example, production, staging).
-
Unique identifier for the asset.
-
Model name or number.
-
Human-readable asset name.
-
The owner of the asset.
-
Serial number of the asset.
-
Vendor or manufacturer.
-
-
Elastic Common Schema (ECS) cloud fields for cloud-hosted entities.
Additional properties are NOT allowed.
Hide cloud attributes Show cloud attributes object
-
Additional properties are NOT allowed.
-
Additional properties are NOT allowed.
-
Additional properties are NOT allowed.
-
Additional properties are NOT allowed.
-
Additional properties are NOT allowed.
-
-
Additional properties are NOT allowed.
Hide entity attributes Show entity attributes object
-
Boolean flags describing characteristics of the entity.
Additional properties are NOT allowed.
Hide attributes attributes Show attributes attributes object
-
Whether the entity is classified as an asset.
-
Known redirect URIs or URLs (e.g. OAuth application callbacks).
-
Whether the entity is managed (for example, via a directory service).
-
Whether multi-factor authentication is enabled for the entity.
-
OAuth consent restriction (e.g. admin_only, verified_only, unrestricted).
-
Action-level permissions granted to this entity (not roles or groups).
-
Storage tier or class assigned to a storage resource (e.g. hot, warm, cold, standard, archive).
-
Watchlist identifiers the entity belongs to (v2).
-
-
Behavioral signals observed for the entity.
Additional properties are NOT allowed.
-
Identifies which engine created this entity (for example, logs_extraction or risk_score_maintainer).
-
Additional properties are NOT allowed.
-
Unique identifier for this entity.
-
Timestamps tracking the entity lifecycle.
Additional properties are NOT allowed.
Hide lifecycle attributes Show lifecycle attributes object
-
When the entity was first observed.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
When the entity last generated activity.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
When the entity was last observed.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$.
-
-
Human-readable name of the entity.
-
Connections between this entity and other entities.
Additional properties are NOT allowed.
Hide relationships attributes Show relationships attributes object
-
Entities this entity accesses frequently.
Additional properties are NOT allowed.
Hide accesses_frequently attributes Show accesses_frequently attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity accesses infrequently.
Additional properties are NOT allowed.
Hide accesses_infrequently attributes Show accesses_infrequently attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity administers (for example, a user who is an admin of a service).
Additional properties are NOT allowed.
Hide administers attributes Show administers attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity communicates with.
Additional properties are NOT allowed.
Hide communicates_with attributes Show communicates_with attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity depends on.
Additional properties are NOT allowed.
Hide depends_on attributes Show depends_on attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities owned by this entity.
Additional properties are NOT allowed.
Hide owns attributes Show owns attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities inferred to be owned by this entity.
Additional properties are NOT allowed.
Hide owns_inferred attributes Show owns_inferred attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Resolution metadata linking this entity to another.
Additional properties are NOT allowed.
Hide resolution attributes Show resolution attributes object
-
entity.id of the entity this one resolves to
-
Aggregated risk score for the resolution group.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Lexical description of the resolution group's aggregated risk.
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the resolution group's aggregated risk score.
-
The normalized numeric value of the resolution group's aggregated risk score.
Minimum value is
0, maximum value is100.
-
-
-
Entities supervised by this entity.
Additional properties are NOT allowed.
Hide supervises attributes Show supervises attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
-
Risk scoring information for the entity.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Lexical description of the entity's risk.
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100.
-
-
Schema version of the entity record.
-
Sources that produced this entity record.
-
Optional sub-type classification for the entity.
-
The entity type.
-
URL associated with the entity.
-
-
Additional properties are NOT allowed.
Hide event attribute Show event attribute object
-
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$.
-
-
Additional properties are allowed.
-
Elastic Common Schema (ECS) orchestrator fields for container-orchestrated entities.
Additional properties are NOT allowed.
Hide orchestrator attributes Show orchestrator attributes object
-
Additional properties are NOT allowed.
-
Additional properties are NOT allowed.
curl -X POST -H "kbn-xsrf: true" -H "Authorization: ApiKey ${API_KEY}" \
-H "Content-Type: application/json" \
-d '{"entity":{"id":"host:web-server-prod-01","name":"web-server-prod-01","type":"host","source":["manual"],"attributes":{"asset":true}},"host":{"name":"web-server-prod-01","ip":["10.0.1.42"]}}' \
"${KIBANA_URL}/api/security/entity_store/entities/host"
POST kbn://api/security/entity_store/entities/host
{
"entity": {
"id": "host:web-server-prod-01",
"name": "web-server-prod-01",
"type": "host",
"source": ["manual"],
"attributes": { "asset": true }
},
"host": {
"name": "web-server-prod-01",
"ip": ["10.0.1.42"]
}
}
{
"asset": {
"business_unit": "Engineering",
"criticality": "high_impact",
"environment": "production"
},
"entity": {
"attributes": {
"asset": true,
"managed": true
},
"id": "host:web-server-prod-01",
"name": "web-server-prod-01",
"source": [
"manual"
],
"type": "host"
},
"host": {
"hostname": [
"web-server-prod-01.example.com"
],
"ip": [
"10.0.1.42"
],
"name": "web-server-prod-01"
}
}
{
"ok": true
}
{
"error": "Bad Request",
"message": "Bad request: Supplied ID my-custom-id does not match generated EUID host:web-server-prod-01",
"statusCode": 400
}
{
"error": "Conflict",
"message": "Entity ID 'host:web-server-prod-01' already exists",
"statusCode": 409
}