Spaces method and path for this operation:
put /s/{space_id}/api/security/entity_store
Refer to Spaces for more information.
Update the Entity Store configuration without reinstalling. Send logExtraction to change log extraction settings. Omitting a log extraction field leaves it unchanged. Sending null for a log extraction field clears that override and reverts to the default. Send historySnapshot.frequency to change the snapshot interval (at least 1 hour) and historySnapshot.retentionDays to change how long snapshots are kept. Omitting either history snapshot field leaves it unchanged. At least one of logExtraction or historySnapshot is required.
[Required authorization] Route required privileges: securitySolution.
PUT
/api/security/entity_store
curl
curl -X PUT -H "kbn-xsrf: true" -H "Authorization: ApiKey ${API_KEY}" \
-H "Content-Type: application/json" \
-d '{"logExtraction":{"lookbackPeriod":"6h","frequency":"10m","fieldHistoryLength":15}}' \
"${KIBANA_URL}/api/security/entity_store"
PUT kbn://api/security/entity_store
{
"logExtraction": {
"lookbackPeriod": "6h",
"frequency": "10m",
"fieldHistoryLength": 15
}
}
curl -X PUT -H "kbn-xsrf: true" -H "Authorization: ApiKey ${API_KEY}" \
-H "Content-Type: application/json" \
-d '{"historySnapshot":{"frequency":"12h","retentionDays":90}}' \
"${KIBANA_URL}/api/security/entity_store"
PUT kbn://api/security/entity_store
{
"historySnapshot": {
"frequency": "12h",
"retentionDays": 90
}
}
Request examples
Clear log extraction overrides
Send null for any field to clear that override and revert it to the default value.
{
"logExtraction": {
"delay": null,
"frequency": null
}
}
Update the history snapshot interval and retention. Omit a field to leave it unchanged.
{
"historySnapshot": {
"frequency": "12h",
"retentionDays": 90
}
}
Update the log extraction configuration with a new lookback period and frequency.
{
"logExtraction": {
"fieldHistoryLength": 15,
"frequency": "10m",
"lookbackPeriod": "6h"
}
}
Response examples (200)
The Entity Store configuration was successfully updated.
{
"ok": true
}
Response examples (400)
Invalid duration parameter
A log extraction parameter has an invalid duration format.
{
"error": "Bad Request",
"message": "[request body]: logExtraction.frequency: must be a valid duration of at least 30 seconds (e.g. 1m, 30s)",
"statusCode": 400
}
The history snapshot interval must be at least 1 hour.
{
"error": "Bad Request",
"message": "[request body]: historySnapshot.frequency: must be a valid duration of at least 1 hour (e.g. 1h, 24h)",
"statusCode": 400
}
Response examples (404)
The Entity Store has not been installed yet.
{
"error": "Not Found",
"message": "Entity store is not installed",
"statusCode": 404
}