Spaces method and path for this operation:
Refer to Spaces for more information.
Update an existing entity record in the Entity Store. By default only certain fields can be updated. Set the force query parameter to true to update protected fields.
[Required authorization] Route required privileges: securitySolution.
Query parameters
-
When true, allows updating protected fields.
Values are
trueorfalse. Default value isfalse.
-
The time the entity record was last updated.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
Additional properties are NOT allowed.
Hide asset attributes Show asset attributes object
-
Business unit the asset belongs to.
-
The criticality level assigned to this asset.
Values are
low_impact,medium_impact,high_impact, orextreme_impact. -
Deployment environment (for example, production, staging).
-
Unique identifier for the asset.
-
Model name or number.
-
Human-readable asset name.
-
The owner of the asset.
-
Serial number of the asset.
-
Vendor or manufacturer.
-
-
Additional properties are NOT allowed.
Hide entity attributes Show entity attributes object
-
Boolean flags describing characteristics of the entity.
Additional properties are NOT allowed.
Hide attributes attributes Show attributes attributes object
-
Whether the entity is classified as an asset.
-
Known redirect URIs or URLs (e.g. OAuth application callbacks).
-
Whether the entity is managed (for example, via a directory service).
-
Whether multi-factor authentication is enabled for the entity.
-
OAuth consent restriction (e.g. admin_only, verified_only, unrestricted).
-
Action-level permissions granted to this entity (not roles or groups).
-
Storage tier or class assigned to a storage resource (e.g. hot, warm, cold, standard, archive).
-
Watchlist identifiers the entity belongs to (v2).
-
-
Behavioral signals observed for the entity.
Additional properties are NOT allowed.
-
Identifies which engine created this entity (for example, logs_extraction or risk_score_maintainer).
-
Additional properties are NOT allowed.
-
Unique identifier for this entity.
-
Timestamps tracking the entity lifecycle.
Additional properties are NOT allowed.
Hide lifecycle attributes Show lifecycle attributes object
-
When the entity was first observed.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
When the entity last generated activity.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
When the entity was last observed.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$.
-
-
Human-readable name of the entity.
-
Connections between this entity and other entities.
Additional properties are NOT allowed.
Hide relationships attributes Show relationships attributes object
-
Entities this entity accesses frequently.
Additional properties are NOT allowed.
Hide accesses_frequently attributes Show accesses_frequently attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity accesses infrequently.
Additional properties are NOT allowed.
Hide accesses_infrequently attributes Show accesses_infrequently attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity administers (for example, a user who is an admin of a service).
Additional properties are NOT allowed.
Hide administers attributes Show administers attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity communicates with.
Additional properties are NOT allowed.
Hide communicates_with attributes Show communicates_with attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity depends on.
Additional properties are NOT allowed.
Hide depends_on attributes Show depends_on attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities owned by this entity.
Additional properties are NOT allowed.
Hide owns attributes Show owns attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities inferred to be owned by this entity.
Additional properties are NOT allowed.
Hide owns_inferred attributes Show owns_inferred attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Resolution metadata linking this entity to another.
Additional properties are NOT allowed.
Hide resolution attributes Show resolution attributes object
-
entity.id of the entity this one resolves to
-
Aggregated risk score for the resolution group.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Lexical description of the resolution group's aggregated risk.
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the resolution group's aggregated risk score.
-
The normalized numeric value of the resolution group's aggregated risk score.
Minimum value is
0, maximum value is100.
-
-
-
Entities supervised by this entity.
Additional properties are NOT allowed.
Hide supervises attributes Show supervises attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
-
Risk scoring information for the entity.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Lexical description of the entity's risk.
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100.
-
-
Schema version of the entity record.
-
Sources that produced this entity record.
-
Optional sub-type classification for the entity.
-
The entity type.
-
URL associated with the entity.
-
-
Additional properties are NOT allowed.
Hide event attribute Show event attribute object
-
When the event was ingested into Elasticsearch.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$.
-
-
Custom key-value labels attached to the entity.
Additional properties are allowed.
-
Tags attached to the entity.
-
Elastic Common Schema (ECS) user fields collected on the entity.
Additional properties are NOT allowed.
Hide user attributes Show user attributes object
-
Observed user domains.
-
Observed email addresses.
-
Observed full names of the user.
-
Observed user hashes.
-
Observed user identifiers.
-
Primary user name.
-
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Lexical description of the entity's risk.
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score.
Minimum value is
0, maximum value is100.
-
-
Observed roles assigned to the user.
-
-
The time the entity record was last updated.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
Additional properties are NOT allowed.
Hide asset attributes Show asset attributes object
-
Business unit the asset belongs to.
-
The criticality level assigned to this asset.
Values are
low_impact,medium_impact,high_impact, orextreme_impact. -
Deployment environment (for example, production, staging).
-
Unique identifier for the asset.
-
Model name or number.
-
Human-readable asset name.
-
The owner of the asset.
-
Serial number of the asset.
-
Vendor or manufacturer.
-
-
Additional properties are NOT allowed.
Hide entity attributes Show entity attributes object
-
Boolean flags describing characteristics of the entity.
Additional properties are NOT allowed.
Hide attributes attributes Show attributes attributes object
-
Whether the entity is classified as an asset.
-
Known redirect URIs or URLs (e.g. OAuth application callbacks).
-
Whether the entity is managed (for example, via a directory service).
-
Whether multi-factor authentication is enabled for the entity.
-
OAuth consent restriction (e.g. admin_only, verified_only, unrestricted).
-
Action-level permissions granted to this entity (not roles or groups).
-
Storage tier or class assigned to a storage resource (e.g. hot, warm, cold, standard, archive).
-
Watchlist identifiers the entity belongs to (v2).
-
-
Behavioral signals observed for the entity.
Additional properties are NOT allowed.
-
Identifies which engine created this entity (for example, logs_extraction or risk_score_maintainer).
-
Additional properties are NOT allowed.
-
Unique identifier for this entity.
-
Timestamps tracking the entity lifecycle.
Additional properties are NOT allowed.
Hide lifecycle attributes Show lifecycle attributes object
-
When the entity was first observed.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
When the entity last generated activity.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
When the entity was last observed.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$.
-
-
Human-readable name of the entity.
-
Connections between this entity and other entities.
Additional properties are NOT allowed.
Hide relationships attributes Show relationships attributes object
-
Entities this entity accesses frequently.
Additional properties are NOT allowed.
Hide accesses_frequently attributes Show accesses_frequently attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity accesses infrequently.
Additional properties are NOT allowed.
Hide accesses_infrequently attributes Show accesses_infrequently attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity administers (for example, a user who is an admin of a service).
Additional properties are NOT allowed.
Hide administers attributes Show administers attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity communicates with.
Additional properties are NOT allowed.
Hide communicates_with attributes Show communicates_with attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity depends on.
Additional properties are NOT allowed.
Hide depends_on attributes Show depends_on attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities owned by this entity.
Additional properties are NOT allowed.
Hide owns attributes Show owns attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities inferred to be owned by this entity.
Additional properties are NOT allowed.
Hide owns_inferred attributes Show owns_inferred attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Resolution metadata linking this entity to another.
Additional properties are NOT allowed.
Hide resolution attributes Show resolution attributes object
-
entity.id of the entity this one resolves to
-
Aggregated risk score for the resolution group.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Lexical description of the resolution group's aggregated risk.
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the resolution group's aggregated risk score.
-
The normalized numeric value of the resolution group's aggregated risk score.
Minimum value is
0, maximum value is100.
-
-
-
Entities supervised by this entity.
Additional properties are NOT allowed.
Hide supervises attributes Show supervises attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
-
Risk scoring information for the entity.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Lexical description of the entity's risk.
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100.
-
-
Schema version of the entity record.
-
Sources that produced this entity record.
-
Optional sub-type classification for the entity.
-
The entity type.
-
URL associated with the entity.
-
-
Additional properties are NOT allowed.
Hide event attribute Show event attribute object
-
When the event was ingested into Elasticsearch.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$.
-
-
Elastic Common Schema (ECS) host fields collected on the entity.
Additional properties are NOT allowed.
Hide host attributes Show host attributes object
-
Observed CPU architectures.
-
Observed host domains.
-
Observed hostnames.
-
Observed host identifiers.
-
Observed IP addresses.
-
Observed MAC addresses.
-
Primary host name.
-
Elastic Common Schema (ECS) host.os fields collected on the entity latest index (v2).
Additional properties are NOT allowed.
Hide os attributes Show os attributes object
-
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Lexical description of the entity's risk.
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score.
Minimum value is
0, maximum value is100.
-
-
Observed host types.
-
-
Custom key-value labels attached to the entity.
Additional properties are allowed.
-
Tags attached to the entity.
-
The time the entity record was last updated.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
Additional properties are NOT allowed.
Hide asset attributes Show asset attributes object
-
Business unit the asset belongs to.
-
The criticality level assigned to this asset.
Values are
low_impact,medium_impact,high_impact, orextreme_impact. -
Deployment environment (for example, production, staging).
-
Unique identifier for the asset.
-
Model name or number.
-
Human-readable asset name.
-
The owner of the asset.
-
Serial number of the asset.
-
Vendor or manufacturer.
-
-
Additional properties are NOT allowed.
Hide entity attributes Show entity attributes object
-
Boolean flags describing characteristics of the entity.
Additional properties are NOT allowed.
Hide attributes attributes Show attributes attributes object
-
Whether the entity is classified as an asset.
-
Known redirect URIs or URLs (e.g. OAuth application callbacks).
-
Whether the entity is managed (for example, via a directory service).
-
Whether multi-factor authentication is enabled for the entity.
-
OAuth consent restriction (e.g. admin_only, verified_only, unrestricted).
-
Action-level permissions granted to this entity (not roles or groups).
-
Storage tier or class assigned to a storage resource (e.g. hot, warm, cold, standard, archive).
-
Watchlist identifiers the entity belongs to (v2).
-
-
Behavioral signals observed for the entity.
Additional properties are NOT allowed.
-
Identifies which engine created this entity (for example, logs_extraction or risk_score_maintainer).
-
Additional properties are NOT allowed.
-
Unique identifier for this entity.
-
Timestamps tracking the entity lifecycle.
Additional properties are NOT allowed.
Hide lifecycle attributes Show lifecycle attributes object
-
When the entity was first observed.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
When the entity last generated activity.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
When the entity was last observed.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$.
-
-
Human-readable name of the entity.
-
Connections between this entity and other entities.
Additional properties are NOT allowed.
Hide relationships attributes Show relationships attributes object
-
Entities this entity accesses frequently.
Additional properties are NOT allowed.
Hide accesses_frequently attributes Show accesses_frequently attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity accesses infrequently.
Additional properties are NOT allowed.
Hide accesses_infrequently attributes Show accesses_infrequently attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity administers (for example, a user who is an admin of a service).
Additional properties are NOT allowed.
Hide administers attributes Show administers attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity communicates with.
Additional properties are NOT allowed.
Hide communicates_with attributes Show communicates_with attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity depends on.
Additional properties are NOT allowed.
Hide depends_on attributes Show depends_on attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities owned by this entity.
Additional properties are NOT allowed.
Hide owns attributes Show owns attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities inferred to be owned by this entity.
Additional properties are NOT allowed.
Hide owns_inferred attributes Show owns_inferred attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Resolution metadata linking this entity to another.
Additional properties are NOT allowed.
Hide resolution attributes Show resolution attributes object
-
entity.id of the entity this one resolves to
-
Aggregated risk score for the resolution group.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Lexical description of the resolution group's aggregated risk.
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the resolution group's aggregated risk score.
-
The normalized numeric value of the resolution group's aggregated risk score.
Minimum value is
0, maximum value is100.
-
-
-
Entities supervised by this entity.
Additional properties are NOT allowed.
Hide supervises attributes Show supervises attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
-
Risk scoring information for the entity.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Lexical description of the entity's risk.
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100.
-
-
Schema version of the entity record.
-
Sources that produced this entity record.
-
Optional sub-type classification for the entity.
-
The entity type.
-
URL associated with the entity.
-
-
Additional properties are NOT allowed.
Hide event attribute Show event attribute object
-
When the event was ingested into Elasticsearch.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$.
-
-
Custom key-value labels attached to the entity.
Additional properties are allowed.
-
Elastic Common Schema (ECS) service fields collected on the entity.
Additional properties are NOT allowed.
Hide service attributes Show service attributes object
-
Service address.
-
Service environment (for example, production, staging).
-
Ephemeral identifier of the service.
-
Unique identifier of the service.
-
Primary service name.
-
Node information for the service.
Additional properties are NOT allowed.
-
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Lexical description of the entity's risk.
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score.
Minimum value is
0, maximum value is100.
-
-
Current state of the service.
-
Service type.
-
Service version.
-
-
Tags attached to the entity.
-
The time the entity record was last updated.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
Additional properties are NOT allowed.
Hide asset attributes Show asset attributes object
-
Business unit the asset belongs to.
-
The criticality level assigned to this asset.
Values are
low_impact,medium_impact,high_impact, orextreme_impact. -
Deployment environment (for example, production, staging).
-
Unique identifier for the asset.
-
Model name or number.
-
Human-readable asset name.
-
The owner of the asset.
-
Serial number of the asset.
-
Vendor or manufacturer.
-
-
Elastic Common Schema (ECS) cloud fields for cloud-hosted entities.
Additional properties are NOT allowed.
Hide cloud attributes Show cloud attributes object
-
Additional properties are NOT allowed.
-
Additional properties are NOT allowed.
-
Additional properties are NOT allowed.
-
Additional properties are NOT allowed.
-
Additional properties are NOT allowed.
-
-
Additional properties are NOT allowed.
Hide entity attributes Show entity attributes object
-
Boolean flags describing characteristics of the entity.
Additional properties are NOT allowed.
Hide attributes attributes Show attributes attributes object
-
Whether the entity is classified as an asset.
-
Known redirect URIs or URLs (e.g. OAuth application callbacks).
-
Whether the entity is managed (for example, via a directory service).
-
Whether multi-factor authentication is enabled for the entity.
-
OAuth consent restriction (e.g. admin_only, verified_only, unrestricted).
-
Action-level permissions granted to this entity (not roles or groups).
-
Storage tier or class assigned to a storage resource (e.g. hot, warm, cold, standard, archive).
-
Watchlist identifiers the entity belongs to (v2).
-
-
Behavioral signals observed for the entity.
Additional properties are NOT allowed.
-
Identifies which engine created this entity (for example, logs_extraction or risk_score_maintainer).
-
Additional properties are NOT allowed.
-
Unique identifier for this entity.
-
Timestamps tracking the entity lifecycle.
Additional properties are NOT allowed.
Hide lifecycle attributes Show lifecycle attributes object
-
When the entity was first observed.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
When the entity last generated activity.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
When the entity was last observed.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$.
-
-
Human-readable name of the entity.
-
Connections between this entity and other entities.
Additional properties are NOT allowed.
Hide relationships attributes Show relationships attributes object
-
Entities this entity accesses frequently.
Additional properties are NOT allowed.
Hide accesses_frequently attributes Show accesses_frequently attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity accesses infrequently.
Additional properties are NOT allowed.
Hide accesses_infrequently attributes Show accesses_infrequently attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity administers (for example, a user who is an admin of a service).
Additional properties are NOT allowed.
Hide administers attributes Show administers attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity communicates with.
Additional properties are NOT allowed.
Hide communicates_with attributes Show communicates_with attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities this entity depends on.
Additional properties are NOT allowed.
Hide depends_on attributes Show depends_on attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities owned by this entity.
Additional properties are NOT allowed.
Hide owns attributes Show owns attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Entities inferred to be owned by this entity.
Additional properties are NOT allowed.
Hide owns_inferred attributes Show owns_inferred attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
Resolution metadata linking this entity to another.
Additional properties are NOT allowed.
Hide resolution attributes Show resolution attributes object
-
entity.id of the entity this one resolves to
-
Aggregated risk score for the resolution group.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Lexical description of the resolution group's aggregated risk.
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the resolution group's aggregated risk score.
-
The normalized numeric value of the resolution group's aggregated risk score.
Minimum value is
0, maximum value is100.
-
-
-
Entities supervised by this entity.
Additional properties are NOT allowed.
Hide supervises attributes Show supervises attributes object
-
Target entity EUIDs for this relationship; used for graph LOOKUP JOIN and DSL filters.
-
Additional properties are NOT allowed.
-
-
-
Risk scoring information for the entity.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Lexical description of the entity's risk.
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100.
-
-
Schema version of the entity record.
-
Sources that produced this entity record.
-
Optional sub-type classification for the entity.
-
The entity type.
-
URL associated with the entity.
-
-
Additional properties are NOT allowed.
Hide event attribute Show event attribute object
-
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$.
-
-
Additional properties are allowed.
-
Elastic Common Schema (ECS) orchestrator fields for container-orchestrated entities.
Additional properties are NOT allowed.
Hide orchestrator attributes Show orchestrator attributes object
-
Additional properties are NOT allowed.
-
Additional properties are NOT allowed.
curl -X PUT -H "kbn-xsrf: true" -H "Authorization: ApiKey ${API_KEY}" \
-H "Content-Type: application/json" \
-d '{"entity":{"id":"user:jane.doe@example.com","name":"jane.doe","type":"user","attributes":{"managed":true,"mfa_enabled":true}},"user":{"name":"jane.doe"}}' \
"${KIBANA_URL}/api/security/entity_store/entities/user?force=true"
PUT kbn://api/security/entity_store/entities/user?force=true
{
"entity": {
"id": "user:jane.doe@example.com",
"name": "jane.doe",
"type": "user",
"attributes": { "managed": true, "mfa_enabled": true }
},
"user": { "name": "jane.doe" }
}
{
"entity": {
"attributes": {
"managed": true,
"mfa_enabled": true
},
"id": "user:jane.doe@example.com",
"lifecycle": {
"last_activity": "2026-04-10T14:30:00.000Z"
},
"name": "jane.doe",
"type": "user"
},
"user": {
"email": [
"jane.doe@example.com"
],
"name": "jane.doe",
"roles": [
"admin",
"analyst"
]
}
}
{
"ok": true
}
{
"error": "Bad Request",
"message": "Bad request: The following attributes are not allowed to be updated without forcing it (?force=true): entity.name, entity.type",
"statusCode": 400
}
{
"error": "Not Found",
"message": "Entity ID 'user:jane.doe@example.com' not found",
"statusCode": 404
}