Spaces method and path for this operation:
post /s/{space_id}/api/entity_analytics/watchlists
Refer to Spaces for more information.
Creates a new entity analytics watchlist with an optional set of entity sources. Watchlists apply a risk score modifier to matched entities.
POST
/api/entity_analytics/watchlists
curl \
--request POST 'https://<KIBANA_URL>/api/entity_analytics/watchlists' \
--header "Authorization: $API_KEY" \
--header "Content-Type: application/json" \
--data '{"description":"High risk vendor watchlist","managed":false,"name":"High Risk Vendors","riskModifier":1.5}'
Request examples
Create watchlist request
{
"description": "High risk vendor watchlist",
"managed": false,
"name": "High Risk Vendors",
"riskModifier": 1.5
}
{
"description": "High risk vendor watchlist",
"entitySources": [
{
"enabled": true,
"identifierField": "user.name",
"indexPattern": "my-sync-index",
"name": "My User Index Source",
"type": "index"
}
],
"managed": false,
"name": "High Risk Vendors",
"riskModifier": 1.5
}
Response examples (200)
{
"createdAt": "2026-01-28T12:00:00.000Z",
"description": "High risk vendor watchlist",
"id": "watchlist-123",
"managed": false,
"name": "High Risk Vendors",
"riskModifier": 1.5,
"updatedAt": "2026-01-28T12:00:00.000Z"
}