Create a saved query

POST /api/osquery/saved_queries

Spaces method and path for this operation:

post /s/{space_id}/api/osquery/saved_queries

Refer to Spaces for more information.

Create and run a saved query.

application/json

Body Required

  • description string

    The saved query description.

  • ecs_mapping object

    Map osquery results columns or static values to Elastic Common Schema (ECS) fields

    Hide ecs_mapping attribute Show ecs_mapping attribute object
    • * object Additional properties
      Hide * attributes Show * attributes object
  • id string

    The ID of a saved query.

  • interval string

    An interval, in seconds, on which to run the query.

  • platform string

    Restricts the query to a specified platform. The default is all platforms. To specify multiple platforms, use commas. For example, linux,darwin.

  • query string

    The SQL query you want to run.

  • removed boolean

    Indicates whether the query is removed.

  • snapshot boolean

    Indicates whether the query is a snapshot.

  • version string

    Uses the Osquery versions greater than or equal to the specified version string.

Responses

  • 200 application/json

    OK

POST /api/osquery/saved_queries
curl \
 --request POST 'https://localhost:5601/api/osquery/saved_queries' \
 --header "Authorization: $API_KEY" \
 --header "Content-Type: application/json" \
 --data '{
  "description": "Saved query description",
  "ecs_mapping": {
    "host.uptime": {
      "field": "total_seconds"
    }
  },
  "id": "saved_query_id",
  "interval": "60",
  "platform": "linux,darwin",
  "query": "select * from uptime;",
  "timeout": 120,
  "version": "2.8.0"
}'