Spaces method and path for this operation:
Refer to Spaces for more information.
List entities records, paging, sorting and filtering as needed.
Query parameters
-
Field to sort results by.
-
Sort order.
Values are
ascordesc. -
Page number to return (1-indexed).
Minimum value is
1. -
Number of entities per page.
Minimum value is
1, maximum value is10000. -
An ES query to filter by.
-
Entity types to include in the results.
Values are
user,host,service, orgeneric.
Responses
-
Entities returned successfully
Hide response attributes Show response attributes object
-
Debug information about the Elasticsearch query executed.
-
Current page number.
Minimum value is
1. -
Number of entities per page.
Minimum value is
1, maximum value is1000. -
The entity records for this page.
An entity record from the Entity Store. The
entitynamespace is a root-level field in the latest index, unlike source logs where it is nested underhost,user, orservice.One of: An entity record representing a user, stored in the Entity Store latest index.
Hide attributes Show attributes
-
The time the entity record was last updated.
-
Asset metadata associated with the entity.
Additional properties are NOT allowed.
Hide asset attributes Show asset attributes object
-
Business unit the asset belongs to.
-
The criticality level of the asset.
Values are
low_impact,medium_impact,high_impact, orextreme_impact. -
Deployment environment (for example, production, staging).
-
Unique identifier for the asset.
-
Model name or number.
-
Human-readable asset name.
-
The owner of the asset.
-
Serial number of the asset.
-
Vendor or manufacturer.
-
-
Core entity fields shared across all entity types. The
entitynamespace is a root-level field in the Entity Store latest index.Additional properties are NOT allowed.
Hide entity attributes Show entity attributes object
-
Boolean flags describing characteristics of the entity.
Additional properties are NOT allowed.
Hide attributes attributes Show attributes attributes object
-
Boolean flags indicating observed behavioral signals.
Additional properties are NOT allowed.
-
Internal metadata attached to an entity by the engine that produced it.
Additional properties are NOT allowed.
-
Unique identifier for this entity.
-
Timestamps tracking the entity lifecycle.
Additional properties are NOT allowed.
-
Human-readable name of the entity.
-
Connections between this entity and other entities.
Additional properties are NOT allowed.
Hide relationships attributes Show relationships attributes object
-
Entity IDs that frequently access this entity.
-
Entity IDs this entity accesses frequently.
-
Entity IDs this entity accesses infrequently.
-
Entity IDs this entity communicates with.
-
Entity IDs that depend on this entity.
-
Entity IDs this entity depends on.
-
Entity IDs that own this entity.
-
Entity IDs owned by this entity.
-
Entity IDs that supervise this entity.
-
Entity IDs supervised by this entity.
-
-
Risk scoring information for the entity.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100.
-
-
The source that produced this entity record.
-
Optional sub-type classification for the entity.
-
The entity type.
-
-
Additional properties are NOT allowed.
-
Elastic Common Schema (ECS) user fields collected on the entity.
Additional properties are NOT allowed.
Hide user attributes Show user attributes object
-
Observed user domains.
-
Observed email addresses.
-
Observed full names of the user.
-
Observed user hashes.
-
Observed user IDs.
-
Primary user name.
-
Hide risk attributes Show risk attributes object
-
The time at which the risk score was calculated.
-
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100. -
Unique identifier for the scoring run that produced this document.
-
The number of risk input documents that contributed to the Category 1 score (
category_1_score). -
The contribution of Category 1 to the overall risk score (
calculated_score). Category 1 contains Detection Engine Alerts. -
The criticality level of the asset.
Values are
low_impact,medium_impact,high_impact, orextreme_impact. -
The identifier field defining this risk score. Coupled with
id_value, uniquely identifies the entity being scored. -
The identifier value defining this risk score. Coupled with
id_field, uniquely identifies the entity being scored. -
A list of the highest-risk documents contributing to this risk score. Useful for investigative purposes.
Hide inputs attributes Show inputs attributes object
A generic representation of a document contributing to a Risk Score.
-
The risk category of the risk input document.
-
A human-readable description of the risk input document.
-
The EUID of the entity within the graph that generated this alert.
-
The unique identifier (
_id) of the original source document -
The unique index (
_index) of the original source document -
The weighted risk score of the risk input document.
Minimum value is
0, maximum value is100. -
The @timestamp of the risk input document.
-
-
A list of modifiers that were applied to the risk score calculation.
-
Distinguishes base, propagated, and resolution scores.
Values are
base,propagated, orresolution.
-
-
Observed roles assigned to the user.
-
An entity record representing a host, stored in the Entity Store latest index.
Hide attributes Show attributes
-
The time the entity record was last updated.
-
Asset metadata associated with the entity.
Additional properties are NOT allowed.
Hide asset attributes Show asset attributes object
-
Business unit the asset belongs to.
-
The criticality level of the asset.
Values are
low_impact,medium_impact,high_impact, orextreme_impact. -
Deployment environment (for example, production, staging).
-
Unique identifier for the asset.
-
Model name or number.
-
Human-readable asset name.
-
The owner of the asset.
-
Serial number of the asset.
-
Vendor or manufacturer.
-
-
Core entity fields shared across all entity types. The
entitynamespace is a root-level field in the Entity Store latest index.Additional properties are NOT allowed.
Hide entity attributes Show entity attributes object
-
Boolean flags describing characteristics of the entity.
Additional properties are NOT allowed.
Hide attributes attributes Show attributes attributes object
-
Boolean flags indicating observed behavioral signals.
Additional properties are NOT allowed.
-
Internal metadata attached to an entity by the engine that produced it.
Additional properties are NOT allowed.
-
Unique identifier for this entity.
-
Timestamps tracking the entity lifecycle.
Additional properties are NOT allowed.
-
Human-readable name of the entity.
-
Connections between this entity and other entities.
Additional properties are NOT allowed.
Hide relationships attributes Show relationships attributes object
-
Entity IDs that frequently access this entity.
-
Entity IDs this entity accesses frequently.
-
Entity IDs this entity accesses infrequently.
-
Entity IDs this entity communicates with.
-
Entity IDs that depend on this entity.
-
Entity IDs this entity depends on.
-
Entity IDs that own this entity.
-
Entity IDs owned by this entity.
-
Entity IDs that supervise this entity.
-
Entity IDs supervised by this entity.
-
-
Risk scoring information for the entity.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100.
-
-
The source that produced this entity record.
-
Optional sub-type classification for the entity.
-
The entity type.
-
-
Additional properties are NOT allowed.
-
Elastic Common Schema (ECS) host fields collected on the entity.
Additional properties are NOT allowed.
Hide host attributes Show host attributes object
-
Observed CPU architectures.
-
Observed host domains.
-
Core entity fields shared across all entity types. The
entitynamespace is a root-level field in the Entity Store latest index.Additional properties are NOT allowed.
Hide entity attributes Show entity attributes object
-
Boolean flags describing characteristics of the entity.
Additional properties are NOT allowed.
Hide attributes attributes Show attributes attributes object
-
Boolean flags indicating observed behavioral signals.
Additional properties are NOT allowed.
-
Internal metadata attached to an entity by the engine that produced it.
Additional properties are NOT allowed.
-
Unique identifier for this entity.
-
Timestamps tracking the entity lifecycle.
Additional properties are NOT allowed.
-
Human-readable name of the entity.
-
Connections between this entity and other entities.
Additional properties are NOT allowed.
Hide relationships attributes Show relationships attributes object
-
Entity IDs that frequently access this entity.
-
Entity IDs this entity accesses frequently.
-
Entity IDs this entity accesses infrequently.
-
Entity IDs this entity communicates with.
-
Entity IDs that depend on this entity.
-
Entity IDs this entity depends on.
-
Entity IDs that own this entity.
-
Entity IDs owned by this entity.
-
Entity IDs that supervise this entity.
-
Entity IDs supervised by this entity.
-
-
Risk scoring information for the entity.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100.
-
-
The source that produced this entity record.
-
Optional sub-type classification for the entity.
-
The entity type.
-
-
Observed hostnames.
-
Observed host IDs.
-
Observed IP addresses.
-
Observed MAC addresses.
-
Primary host name.
-
Elastic Common Schema (ECS) host.os fields collected on the entity latest index.
Additional properties are NOT allowed.
Hide os attributes Show os attributes object
-
Hide risk attributes Show risk attributes object
-
The time at which the risk score was calculated.
-
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100. -
Unique identifier for the scoring run that produced this document.
-
The number of risk input documents that contributed to the Category 1 score (
category_1_score). -
The contribution of Category 1 to the overall risk score (
calculated_score). Category 1 contains Detection Engine Alerts. -
The criticality level of the asset.
Values are
low_impact,medium_impact,high_impact, orextreme_impact. -
The identifier field defining this risk score. Coupled with
id_value, uniquely identifies the entity being scored. -
The identifier value defining this risk score. Coupled with
id_field, uniquely identifies the entity being scored. -
A list of the highest-risk documents contributing to this risk score. Useful for investigative purposes.
Hide inputs attributes Show inputs attributes object
A generic representation of a document contributing to a Risk Score.
-
The risk category of the risk input document.
-
A human-readable description of the risk input document.
-
The EUID of the entity within the graph that generated this alert.
-
The unique identifier (
_id) of the original source document -
The unique index (
_index) of the original source document -
The weighted risk score of the risk input document.
Minimum value is
0, maximum value is100. -
The @timestamp of the risk input document.
-
-
A list of modifiers that were applied to the risk score calculation.
-
Distinguishes base, propagated, and resolution scores.
Values are
base,propagated, orresolution.
-
-
Observed host types.
-
An entity record representing a service, stored in the Entity Store latest index.
Hide attributes Show attributes
-
The time the entity record was last updated.
-
Asset metadata associated with the entity.
Additional properties are NOT allowed.
Hide asset attributes Show asset attributes object
-
Business unit the asset belongs to.
-
The criticality level of the asset.
Values are
low_impact,medium_impact,high_impact, orextreme_impact. -
Deployment environment (for example, production, staging).
-
Unique identifier for the asset.
-
Model name or number.
-
Human-readable asset name.
-
The owner of the asset.
-
Serial number of the asset.
-
Vendor or manufacturer.
-
-
Core entity fields shared across all entity types. The
entitynamespace is a root-level field in the Entity Store latest index.Additional properties are NOT allowed.
Hide entity attributes Show entity attributes object
-
Boolean flags describing characteristics of the entity.
Additional properties are NOT allowed.
Hide attributes attributes Show attributes attributes object
-
Boolean flags indicating observed behavioral signals.
Additional properties are NOT allowed.
-
Internal metadata attached to an entity by the engine that produced it.
Additional properties are NOT allowed.
-
Unique identifier for this entity.
-
Timestamps tracking the entity lifecycle.
Additional properties are NOT allowed.
-
Human-readable name of the entity.
-
Connections between this entity and other entities.
Additional properties are NOT allowed.
Hide relationships attributes Show relationships attributes object
-
Entity IDs that frequently access this entity.
-
Entity IDs this entity accesses frequently.
-
Entity IDs this entity accesses infrequently.
-
Entity IDs this entity communicates with.
-
Entity IDs that depend on this entity.
-
Entity IDs this entity depends on.
-
Entity IDs that own this entity.
-
Entity IDs owned by this entity.
-
Entity IDs that supervise this entity.
-
Entity IDs supervised by this entity.
-
-
Risk scoring information for the entity.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100.
-
-
The source that produced this entity record.
-
Optional sub-type classification for the entity.
-
The entity type.
-
-
Additional properties are NOT allowed.
-
Elastic Common Schema (ECS) service fields collected on the entity.
Additional properties are NOT allowed.
Hide service attributes Show service attributes object
-
Core entity fields shared across all entity types. The
entitynamespace is a root-level field in the Entity Store latest index.Additional properties are NOT allowed.
Hide entity attributes Show entity attributes object
-
Boolean flags describing characteristics of the entity.
Additional properties are NOT allowed.
Hide attributes attributes Show attributes attributes object
-
Boolean flags indicating observed behavioral signals.
Additional properties are NOT allowed.
-
Internal metadata attached to an entity by the engine that produced it.
Additional properties are NOT allowed.
-
Unique identifier for this entity.
-
Timestamps tracking the entity lifecycle.
Additional properties are NOT allowed.
-
Human-readable name of the entity.
-
Connections between this entity and other entities.
Additional properties are NOT allowed.
Hide relationships attributes Show relationships attributes object
-
Entity IDs that frequently access this entity.
-
Entity IDs this entity accesses frequently.
-
Entity IDs this entity accesses infrequently.
-
Entity IDs this entity communicates with.
-
Entity IDs that depend on this entity.
-
Entity IDs this entity depends on.
-
Entity IDs that own this entity.
-
Entity IDs owned by this entity.
-
Entity IDs that supervise this entity.
-
Entity IDs supervised by this entity.
-
-
Risk scoring information for the entity.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100.
-
-
The source that produced this entity record.
-
Optional sub-type classification for the entity.
-
The entity type.
-
-
Primary service name.
-
Hide risk attributes Show risk attributes object
-
The time at which the risk score was calculated.
-
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100. -
Unique identifier for the scoring run that produced this document.
-
The number of risk input documents that contributed to the Category 1 score (
category_1_score). -
The contribution of Category 1 to the overall risk score (
calculated_score). Category 1 contains Detection Engine Alerts. -
The criticality level of the asset.
Values are
low_impact,medium_impact,high_impact, orextreme_impact. -
The identifier field defining this risk score. Coupled with
id_value, uniquely identifies the entity being scored. -
The identifier value defining this risk score. Coupled with
id_field, uniquely identifies the entity being scored. -
A list of the highest-risk documents contributing to this risk score. Useful for investigative purposes.
Hide inputs attributes Show inputs attributes object
A generic representation of a document contributing to a Risk Score.
-
The risk category of the risk input document.
-
A human-readable description of the risk input document.
-
The EUID of the entity within the graph that generated this alert.
-
The unique identifier (
_id) of the original source document -
The unique index (
_index) of the original source document -
The weighted risk score of the risk input document.
Minimum value is
0, maximum value is100. -
The @timestamp of the risk input document.
-
-
A list of modifiers that were applied to the risk score calculation.
-
Distinguishes base, propagated, and resolution scores.
Values are
base,propagated, orresolution.
-
-
A generic entity record. Maps only the
entityandassetnamespaces. Add additional field mappings here as needed.Hide attributes Show attributes
-
The time the entity record was last updated.
-
Asset metadata associated with the entity.
Additional properties are NOT allowed.
Hide asset attributes Show asset attributes object
-
Business unit the asset belongs to.
-
The criticality level of the asset.
Values are
low_impact,medium_impact,high_impact, orextreme_impact. -
Deployment environment (for example, production, staging).
-
Unique identifier for the asset.
-
Model name or number.
-
Human-readable asset name.
-
The owner of the asset.
-
Serial number of the asset.
-
Vendor or manufacturer.
-
-
Core entity fields shared across all entity types. The
entitynamespace is a root-level field in the Entity Store latest index.Additional properties are NOT allowed.
Hide entity attributes Show entity attributes object
-
Boolean flags describing characteristics of the entity.
Additional properties are NOT allowed.
Hide attributes attributes Show attributes attributes object
-
Boolean flags indicating observed behavioral signals.
Additional properties are NOT allowed.
-
Internal metadata attached to an entity by the engine that produced it.
Additional properties are NOT allowed.
-
Unique identifier for this entity.
-
Timestamps tracking the entity lifecycle.
Additional properties are NOT allowed.
-
Human-readable name of the entity.
-
Connections between this entity and other entities.
Additional properties are NOT allowed.
Hide relationships attributes Show relationships attributes object
-
Entity IDs that frequently access this entity.
-
Entity IDs this entity accesses frequently.
-
Entity IDs this entity accesses infrequently.
-
Entity IDs this entity communicates with.
-
Entity IDs that depend on this entity.
-
Entity IDs this entity depends on.
-
Entity IDs that own this entity.
-
Entity IDs owned by this entity.
-
Entity IDs that supervise this entity.
-
Entity IDs supervised by this entity.
-
-
Risk scoring information for the entity.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100.
-
-
The source that produced this entity record.
-
Optional sub-type classification for the entity.
-
The entity type.
-
-
-
Total number of entities matching the query.
Minimum value is
0.
-
curl \
--request GET 'https://<KIBANA_URL>/api/entity_store/entities/list?entity_types=user' \
--header "Authorization: $API_KEY"