Spaces method and path for this operation:
get /s/{space_id}/api/security/entity_store/resolution/rules
Refer to Spaces for more information.
List managed entity resolution rules and their effective enabled state for this space. Each rule description states what it bridges, which data sources it needs, and when to disable it.
[Required authorization] Route required privileges: securitySolution AND securitySolution-entity-analytics.
GET
/api/security/entity_store/resolution/rules
curl \
--request GET 'https://<KIBANA_URL>/api/security/entity_store/resolution/rules' \
--header "Authorization: $API_KEY"
Response examples (200)
Lists the managed resolution rules and their enabled state in the current space.
{
"rules": [
{
"description": "Links user entities that share the same email address, compared case-insensitively, across identity providers. Disable if shared mailboxes or role accounts produce false links.",
"enabled": true,
"id": "email_exact_match",
"kind": "same_field",
"managed": true
},
{
"description": "Links Windows and system account-management (IAM) entities to Active Directory by SID (`user.id`), excluding well-known SIDs such as LocalSystem. Needs Windows/system IAM events and Active Directory entity analytics. Disable if well-known SID exclusions are not enough for your environment.",
"enabled": true,
"id": "windows_sid_bridge",
"kind": "same_field",
"managed": true
},
{
"description": "Links Microsoft Defender (`m365_defender`) identities to Entra ID by GUID-shaped `user.id`. Needs Defender identity events and Entra entity analytics. Disable if Defender SID IAM events leak through the GUID gate.",
"enabled": true,
"id": "entra_guid_bridge",
"kind": "same_field",
"managed": true
},
{
"description": "Links CrowdStrike user entities to Active Directory by SID-prefixed `user.id` (filters out Linux UIDs). Needs CrowdStrike FDR IAM events and Active Directory entity analytics. Disable if CrowdStrike SID coverage is noisy in your tenant.",
"enabled": true,
"id": "crowdstrike_sid_bridge",
"kind": "same_field",
"managed": true
},
{
"description": "Links Microsoft 365 audit actors (`user.id` UPN) to Entra users (`user.name` UPN), compared case-insensitively. Needs o365 audit user-lifecycle events and Entra entity analytics. Covers admins who perform AAD user operations; disable if that population should stay separate.",
"enabled": true,
"id": "upn_cross_field_bridge",
"kind": "cross_field",
"managed": true
},
{
"description": "Related user alias resolution across identity providers",
"enabled": false,
"id": "related_user_alias_resolution",
"kind": "related_user_alias_resolution",
"managed": true
}
]
}