Spaces method and path for this operation:
Refer to Spaces for more information.
Update multiple entity records in the Entity Store in a single request.
[Required authorization] Route required privileges: securitySolution.
Query parameters
-
When true, allows updating protected fields.
Values are
trueorfalse. Default value isfalse.
Body
-
The entities to update.
Hide entities attributes Show entities attributes object
- doc
object Any of: Hide attributes Show attributes
-
The time the entity record was last updated.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
Additional properties are NOT allowed.
Hide asset attributes Show asset attributes object
-
Business unit the asset belongs to.
-
The criticality level assigned to this asset.
Values are
low_impact,medium_impact,high_impact, orextreme_impact. -
Deployment environment (for example, production, staging).
-
Unique identifier for the asset.
-
Model name or number.
-
Human-readable asset name.
-
The owner of the asset.
-
Serial number of the asset.
-
Vendor or manufacturer.
-
-
Additional properties are NOT allowed.
Hide entity attributes Show entity attributes object
-
Boolean flags describing characteristics of the entity.
Additional properties are NOT allowed.
Hide attributes attributes Show attributes attributes object
-
Whether the entity is classified as an asset.
-
Known redirect URIs or URLs (e.g. OAuth application callbacks).
-
Whether the entity is managed (for example, via a directory service).
-
Whether multi-factor authentication is enabled for the entity.
-
OAuth consent restriction (e.g. admin_only, verified_only, unrestricted).
-
Action-level permissions granted to this entity (not roles or groups).
-
Storage tier or class assigned to a storage resource (e.g. hot, warm, cold, standard, archive).
-
Watchlist identifiers the entity belongs to (v2).
-
-
Behavioral signals observed for the entity.
Additional properties are NOT allowed.
-
Identifies which engine created this entity (for example, logs_extraction or risk_score_maintainer).
-
Additional properties are NOT allowed.
-
Unique identifier for this entity.
-
Timestamps tracking the entity lifecycle.
Additional properties are NOT allowed.
Hide lifecycle attributes Show lifecycle attributes object
-
When the entity was first observed.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
When the entity last generated activity.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
When the entity was last observed.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$.
-
-
Human-readable name of the entity.
-
Connections between this entity and other entities.
Additional properties are NOT allowed.
Hide relationships attributes Show relationships attributes object
-
Entities this entity accesses frequently.
Additional properties are NOT allowed.
Hide accesses_frequently attributes Show accesses_frequently attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity accesses infrequently.
Additional properties are NOT allowed.
Hide accesses_infrequently attributes Show accesses_infrequently attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity administers (for example, a user who is an admin of a service).
Additional properties are NOT allowed.
Hide administers attributes Show administers attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity communicates with.
Additional properties are NOT allowed.
Hide communicates_with attributes Show communicates_with attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity depends on.
Additional properties are NOT allowed.
Hide depends_on attributes Show depends_on attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities owned by this entity.
Additional properties are NOT allowed.
Hide owns attributes Show owns attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities inferred to be owned by this entity.
Additional properties are NOT allowed.
Hide owns_inferred attributes Show owns_inferred attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Resolution metadata linking this entity to another.
Additional properties are NOT allowed.
Hide resolution attributes Show resolution attributes object
-
entity.id of the entity this one resolves to
-
Aggregated risk score for the resolution group.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Lexical description of the resolution group's aggregated risk.
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the resolution group's aggregated risk score.
-
The normalized numeric value of the resolution group's aggregated risk score.
Minimum value is
0, maximum value is100.
-
-
-
Entities supervised by this entity.
Additional properties are NOT allowed.
Hide supervises attributes Show supervises attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
-
Risk scoring information for the entity.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Lexical description of the entity's risk.
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100.
-
-
Schema version of the entity record.
-
Sources that produced this entity record.
-
Optional sub-type classification for the entity.
-
The entity type.
-
URL associated with the entity.
-
-
Additional properties are NOT allowed.
Hide event attribute Show event attribute object
-
When the event was ingested into Elasticsearch.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$.
-
-
Custom key-value labels attached to the entity.
Additional properties are allowed.
-
Tags attached to the entity.
-
Elastic Common Schema (ECS) user fields collected on the entity.
Additional properties are NOT allowed.
Hide user attributes Show user attributes object
-
Observed user domains.
-
Observed email addresses.
-
Observed full names of the user.
-
Observed user hashes.
-
Observed user identifiers.
-
Primary user name.
-
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Lexical description of the entity's risk.
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score.
Minimum value is
0, maximum value is100.
-
-
Observed roles assigned to the user.
-
Hide attributes Show attributes
-
The time the entity record was last updated.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
Additional properties are NOT allowed.
Hide asset attributes Show asset attributes object
-
Business unit the asset belongs to.
-
The criticality level assigned to this asset.
Values are
low_impact,medium_impact,high_impact, orextreme_impact. -
Deployment environment (for example, production, staging).
-
Unique identifier for the asset.
-
Model name or number.
-
Human-readable asset name.
-
The owner of the asset.
-
Serial number of the asset.
-
Vendor or manufacturer.
-
-
Additional properties are NOT allowed.
Hide entity attributes Show entity attributes object
-
Boolean flags describing characteristics of the entity.
Additional properties are NOT allowed.
Hide attributes attributes Show attributes attributes object
-
Whether the entity is classified as an asset.
-
Known redirect URIs or URLs (e.g. OAuth application callbacks).
-
Whether the entity is managed (for example, via a directory service).
-
Whether multi-factor authentication is enabled for the entity.
-
OAuth consent restriction (e.g. admin_only, verified_only, unrestricted).
-
Action-level permissions granted to this entity (not roles or groups).
-
Storage tier or class assigned to a storage resource (e.g. hot, warm, cold, standard, archive).
-
Watchlist identifiers the entity belongs to (v2).
-
-
Behavioral signals observed for the entity.
Additional properties are NOT allowed.
-
Identifies which engine created this entity (for example, logs_extraction or risk_score_maintainer).
-
Additional properties are NOT allowed.
-
Unique identifier for this entity.
-
Timestamps tracking the entity lifecycle.
Additional properties are NOT allowed.
Hide lifecycle attributes Show lifecycle attributes object
-
When the entity was first observed.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
When the entity last generated activity.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
When the entity was last observed.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$.
-
-
Human-readable name of the entity.
-
Connections between this entity and other entities.
Additional properties are NOT allowed.
Hide relationships attributes Show relationships attributes object
-
Entities this entity accesses frequently.
Additional properties are NOT allowed.
Hide accesses_frequently attributes Show accesses_frequently attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity accesses infrequently.
Additional properties are NOT allowed.
Hide accesses_infrequently attributes Show accesses_infrequently attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity administers (for example, a user who is an admin of a service).
Additional properties are NOT allowed.
Hide administers attributes Show administers attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity communicates with.
Additional properties are NOT allowed.
Hide communicates_with attributes Show communicates_with attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity depends on.
Additional properties are NOT allowed.
Hide depends_on attributes Show depends_on attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities owned by this entity.
Additional properties are NOT allowed.
Hide owns attributes Show owns attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities inferred to be owned by this entity.
Additional properties are NOT allowed.
Hide owns_inferred attributes Show owns_inferred attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Resolution metadata linking this entity to another.
Additional properties are NOT allowed.
Hide resolution attributes Show resolution attributes object
-
entity.id of the entity this one resolves to
-
Aggregated risk score for the resolution group.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Lexical description of the resolution group's aggregated risk.
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the resolution group's aggregated risk score.
-
The normalized numeric value of the resolution group's aggregated risk score.
Minimum value is
0, maximum value is100.
-
-
-
Entities supervised by this entity.
Additional properties are NOT allowed.
Hide supervises attributes Show supervises attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
-
Risk scoring information for the entity.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Lexical description of the entity's risk.
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100.
-
-
Schema version of the entity record.
-
Sources that produced this entity record.
-
Optional sub-type classification for the entity.
-
The entity type.
-
URL associated with the entity.
-
-
Additional properties are NOT allowed.
Hide event attribute Show event attribute object
-
When the event was ingested into Elasticsearch.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$.
-
-
Elastic Common Schema (ECS) host fields collected on the entity.
Additional properties are NOT allowed.
Hide host attributes Show host attributes object
-
Observed CPU architectures.
-
Observed host domains.
-
Observed hostnames.
-
Observed host identifiers.
-
Observed IP addresses.
-
Observed MAC addresses.
-
Primary host name.
-
Elastic Common Schema (ECS) host.os fields collected on the entity latest index (v2).
Additional properties are NOT allowed.
Hide os attributes Show os attributes object
-
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Lexical description of the entity's risk.
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score.
Minimum value is
0, maximum value is100.
-
-
Observed host types.
-
-
Custom key-value labels attached to the entity.
Additional properties are allowed.
-
Tags attached to the entity.
Hide attributes Show attributes
-
The time the entity record was last updated.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
Additional properties are NOT allowed.
Hide asset attributes Show asset attributes object
-
Business unit the asset belongs to.
-
The criticality level assigned to this asset.
Values are
low_impact,medium_impact,high_impact, orextreme_impact. -
Deployment environment (for example, production, staging).
-
Unique identifier for the asset.
-
Model name or number.
-
Human-readable asset name.
-
The owner of the asset.
-
Serial number of the asset.
-
Vendor or manufacturer.
-
-
Additional properties are NOT allowed.
Hide entity attributes Show entity attributes object
-
Boolean flags describing characteristics of the entity.
Additional properties are NOT allowed.
Hide attributes attributes Show attributes attributes object
-
Whether the entity is classified as an asset.
-
Known redirect URIs or URLs (e.g. OAuth application callbacks).
-
Whether the entity is managed (for example, via a directory service).
-
Whether multi-factor authentication is enabled for the entity.
-
OAuth consent restriction (e.g. admin_only, verified_only, unrestricted).
-
Action-level permissions granted to this entity (not roles or groups).
-
Storage tier or class assigned to a storage resource (e.g. hot, warm, cold, standard, archive).
-
Watchlist identifiers the entity belongs to (v2).
-
-
Behavioral signals observed for the entity.
Additional properties are NOT allowed.
-
Identifies which engine created this entity (for example, logs_extraction or risk_score_maintainer).
-
Additional properties are NOT allowed.
-
Unique identifier for this entity.
-
Timestamps tracking the entity lifecycle.
Additional properties are NOT allowed.
Hide lifecycle attributes Show lifecycle attributes object
-
When the entity was first observed.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
When the entity last generated activity.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
When the entity was last observed.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$.
-
-
Human-readable name of the entity.
-
Connections between this entity and other entities.
Additional properties are NOT allowed.
Hide relationships attributes Show relationships attributes object
-
Entities this entity accesses frequently.
Additional properties are NOT allowed.
Hide accesses_frequently attributes Show accesses_frequently attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity accesses infrequently.
Additional properties are NOT allowed.
Hide accesses_infrequently attributes Show accesses_infrequently attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity administers (for example, a user who is an admin of a service).
Additional properties are NOT allowed.
Hide administers attributes Show administers attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity communicates with.
Additional properties are NOT allowed.
Hide communicates_with attributes Show communicates_with attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity depends on.
Additional properties are NOT allowed.
Hide depends_on attributes Show depends_on attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities owned by this entity.
Additional properties are NOT allowed.
Hide owns attributes Show owns attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities inferred to be owned by this entity.
Additional properties are NOT allowed.
Hide owns_inferred attributes Show owns_inferred attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Resolution metadata linking this entity to another.
Additional properties are NOT allowed.
Hide resolution attributes Show resolution attributes object
-
entity.id of the entity this one resolves to
-
Aggregated risk score for the resolution group.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Lexical description of the resolution group's aggregated risk.
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the resolution group's aggregated risk score.
-
The normalized numeric value of the resolution group's aggregated risk score.
Minimum value is
0, maximum value is100.
-
-
-
Entities supervised by this entity.
Additional properties are NOT allowed.
Hide supervises attributes Show supervises attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
-
Risk scoring information for the entity.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Lexical description of the entity's risk.
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100.
-
-
Schema version of the entity record.
-
Sources that produced this entity record.
-
Optional sub-type classification for the entity.
-
The entity type.
-
URL associated with the entity.
-
-
Additional properties are NOT allowed.
Hide event attribute Show event attribute object
-
When the event was ingested into Elasticsearch.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$.
-
-
Custom key-value labels attached to the entity.
Additional properties are allowed.
-
Elastic Common Schema (ECS) service fields collected on the entity.
Additional properties are NOT allowed.
Hide service attributes Show service attributes object
-
Service address.
-
Service environment (for example, production, staging).
-
Ephemeral identifier of the service.
-
Unique identifier of the service.
-
Primary service name.
-
Node information for the service.
Additional properties are NOT allowed.
-
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Lexical description of the entity's risk.
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score.
Minimum value is
0, maximum value is100.
-
-
Current state of the service.
-
Service type.
-
Service version.
-
-
Tags attached to the entity.
Hide attributes Show attributes
-
The time the entity record was last updated.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
Additional properties are NOT allowed.
Hide asset attributes Show asset attributes object
-
Business unit the asset belongs to.
-
The criticality level assigned to this asset.
Values are
low_impact,medium_impact,high_impact, orextreme_impact. -
Deployment environment (for example, production, staging).
-
Unique identifier for the asset.
-
Model name or number.
-
Human-readable asset name.
-
The owner of the asset.
-
Serial number of the asset.
-
Vendor or manufacturer.
-
-
Elastic Common Schema (ECS) cloud fields for cloud-hosted entities.
Additional properties are NOT allowed.
Hide cloud attributes Show cloud attributes object
-
Additional properties are NOT allowed.
-
Additional properties are NOT allowed.
-
Additional properties are NOT allowed.
-
Additional properties are NOT allowed.
-
Additional properties are NOT allowed.
-
-
Additional properties are NOT allowed.
Hide entity attributes Show entity attributes object
-
Boolean flags describing characteristics of the entity.
Additional properties are NOT allowed.
Hide attributes attributes Show attributes attributes object
-
Whether the entity is classified as an asset.
-
Known redirect URIs or URLs (e.g. OAuth application callbacks).
-
Whether the entity is managed (for example, via a directory service).
-
Whether multi-factor authentication is enabled for the entity.
-
OAuth consent restriction (e.g. admin_only, verified_only, unrestricted).
-
Action-level permissions granted to this entity (not roles or groups).
-
Storage tier or class assigned to a storage resource (e.g. hot, warm, cold, standard, archive).
-
Watchlist identifiers the entity belongs to (v2).
-
-
Behavioral signals observed for the entity.
Additional properties are NOT allowed.
-
Identifies which engine created this entity (for example, logs_extraction or risk_score_maintainer).
-
Additional properties are NOT allowed.
-
Unique identifier for this entity.
-
Timestamps tracking the entity lifecycle.
Additional properties are NOT allowed.
Hide lifecycle attributes Show lifecycle attributes object
-
When the entity was first observed.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
When the entity last generated activity.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
When the entity was last observed.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$.
-
-
Human-readable name of the entity.
-
Connections between this entity and other entities.
Additional properties are NOT allowed.
Hide relationships attributes Show relationships attributes object
-
Entities this entity accesses frequently.
Additional properties are NOT allowed.
Hide accesses_frequently attributes Show accesses_frequently attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity accesses infrequently.
Additional properties are NOT allowed.
Hide accesses_infrequently attributes Show accesses_infrequently attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity administers (for example, a user who is an admin of a service).
Additional properties are NOT allowed.
Hide administers attributes Show administers attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity communicates with.
Additional properties are NOT allowed.
Hide communicates_with attributes Show communicates_with attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity depends on.
Additional properties are NOT allowed.
Hide depends_on attributes Show depends_on attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities owned by this entity.
Additional properties are NOT allowed.
Hide owns attributes Show owns attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities inferred to be owned by this entity.
Additional properties are NOT allowed.
Hide owns_inferred attributes Show owns_inferred attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Resolution metadata linking this entity to another.
Additional properties are NOT allowed.
Hide resolution attributes Show resolution attributes object
-
entity.id of the entity this one resolves to
-
Aggregated risk score for the resolution group.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Lexical description of the resolution group's aggregated risk.
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the resolution group's aggregated risk score.
-
The normalized numeric value of the resolution group's aggregated risk score.
Minimum value is
0, maximum value is100.
-
-
-
Entities supervised by this entity.
Additional properties are NOT allowed.
Hide supervises attributes Show supervises attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
-
Risk scoring information for the entity.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Lexical description of the entity's risk.
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100.
-
-
Schema version of the entity record.
-
Sources that produced this entity record.
-
Optional sub-type classification for the entity.
-
The entity type.
-
URL associated with the entity.
-
-
Additional properties are NOT allowed.
Hide event attribute Show event attribute object
-
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$.
-
-
Additional properties are allowed.
-
Elastic Common Schema (ECS) orchestrator fields for container-orchestrated entities.
Additional properties are NOT allowed.
Hide orchestrator attributes Show orchestrator attributes object
-
Additional properties are NOT allowed.
-
Additional properties are NOT allowed.
-
-
The entity type of this record.
Values are
user,host,service, orgeneric.
curl -X PUT -H "kbn-xsrf: true" -H "Authorization: ApiKey ${API_KEY}" \
-H "Content-Type: application/json" \
-d '{"entities":[{"type":"host","doc":{"entity":{"id":"host:web-server-prod-01","name":"web-server-prod-01","type":"host","attributes":{"asset":true}},"host":{"name":"web-server-prod-01"}}}]}' \
"${KIBANA_URL}/api/security/entity_store/entities/bulk?force=true"
PUT kbn://api/security/entity_store/entities/bulk?force=true
{
"entities": [
{
"type": "host",
"doc": {
"entity": {
"id": "host:web-server-prod-01",
"name": "web-server-prod-01",
"type": "host",
"attributes": { "asset": true }
},
"host": { "name": "web-server-prod-01" }
}
}
]
}
{
"entities": [
{
"doc": {
"entity": {
"attributes": {
"asset": true
},
"id": "host:web-server-prod-01",
"name": "web-server-prod-01",
"type": "host"
},
"host": {
"name": "web-server-prod-01"
}
},
"type": "host"
},
{
"doc": {
"entity": {
"attributes": {
"managed": true
},
"id": "user:jane.doe@example.com",
"name": "jane.doe",
"type": "user"
},
"user": {
"name": "jane.doe"
}
},
"type": "user"
}
]
}
{
"errors": [
{
"_id": "5de9f93a68a72532e736bf5a6184b06300b9cabf",
"reason": "[5de9f93a68a72532e736bf5a6184b06300b9cabf]: document missing",
"status": 404,
"type": "document_missing_exception"
}
],
"ok": true
}
{
"errors": [],
"ok": true
}
{
"error": "Bad Request",
"message": "Bad request: The following attributes are not allowed to be updated without forcing it (?force=true): entity.name, entity.type",
"statusCode": 400
}