Spaces method and path for this operation:
Refer to Spaces for more information.
Update or create an entity in Entity Store.
If the specified entity already exists, it is updated with the provided values. If the entity does not exist, a new one is created. By default, only the following fields can be updated: * entity.attributes.* * entity.lifecycle.* * entity.behavior.* To update other fields, set the force query parameter to true. > info > Some fields always retain the first observed value. Updates to these fields will not appear in the final index.
Due to technical limitations, not all updates are guaranteed to appear in the final list of observed values. Due to technical limitations, create is an async operation. The time for a document to be present in the > final index depends on the entity store transform and usually takes more than 1 minute.
Body
object
Required
An entity record from the Entity Store. The entity namespace is a root-level field in the latest index, unlike source logs where it is nested under host, user, or service.
An entity record representing a user, stored in the Entity Store latest index.
-
The time the entity record was last updated.
-
Asset metadata associated with the entity.
Additional properties are NOT allowed.
Hide asset attributes Show asset attributes object
-
Business unit the asset belongs to.
-
The criticality level of the asset.
Values are
low_impact,medium_impact,high_impact, orextreme_impact. -
Deployment environment (for example, production, staging).
-
Unique identifier for the asset.
-
Model name or number.
-
Human-readable asset name.
-
The owner of the asset.
-
Serial number of the asset.
-
Vendor or manufacturer.
-
-
Core entity fields shared across all entity types. The
entitynamespace is a root-level field in the Entity Store latest index.Additional properties are NOT allowed.
Hide entity attributes Show entity attributes object
-
Boolean flags describing characteristics of the entity.
Additional properties are NOT allowed.
Hide attributes attributes Show attributes attributes object
-
Boolean flags indicating observed behavioral signals.
Additional properties are NOT allowed.
-
Internal metadata attached to an entity by the engine that produced it.
Additional properties are NOT allowed.
-
Unique identifier for this entity.
-
Timestamps tracking the entity lifecycle.
Additional properties are NOT allowed.
-
Human-readable name of the entity.
-
Connections between this entity and other entities.
Additional properties are NOT allowed.
Hide relationships attributes Show relationships attributes object
-
Entity IDs that frequently access this entity.
-
Entity IDs this entity accesses frequently.
-
Entity IDs this entity accesses infrequently.
-
Entity IDs this entity communicates with.
-
Entity IDs that depend on this entity.
-
Entity IDs this entity depends on.
-
Entity IDs that own this entity.
-
Entity IDs owned by this entity.
-
Entity IDs that supervise this entity.
-
Entity IDs supervised by this entity.
-
-
Risk scoring information for the entity.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100.
-
-
The source that produced this entity record.
-
Optional sub-type classification for the entity.
-
The entity type.
-
-
Additional properties are NOT allowed.
-
Elastic Common Schema (ECS) user fields collected on the entity.
Additional properties are NOT allowed.
Hide user attributes Show user attributes object
-
Observed user domains.
-
Observed email addresses.
-
Observed full names of the user.
-
Observed user hashes.
-
Observed user IDs.
-
Primary user name.
-
Hide risk attributes Show risk attributes object
-
The time at which the risk score was calculated.
-
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100. -
Unique identifier for the scoring run that produced this document.
-
The number of risk input documents that contributed to the Category 1 score (
category_1_score). -
The contribution of Category 1 to the overall risk score (
calculated_score). Category 1 contains Detection Engine Alerts. -
The criticality level of the asset.
Values are
low_impact,medium_impact,high_impact, orextreme_impact. -
The identifier field defining this risk score. Coupled with
id_value, uniquely identifies the entity being scored. -
The identifier value defining this risk score. Coupled with
id_field, uniquely identifies the entity being scored. -
A list of the highest-risk documents contributing to this risk score. Useful for investigative purposes.
Hide inputs attributes Show inputs attributes object
A generic representation of a document contributing to a Risk Score.
-
The risk category of the risk input document.
-
A human-readable description of the risk input document.
-
The EUID of the entity within the graph that generated this alert.
-
The unique identifier (
_id) of the original source document -
The unique index (
_index) of the original source document -
The weighted risk score of the risk input document.
Minimum value is
0, maximum value is100. -
The @timestamp of the risk input document.
-
-
A list of modifiers that were applied to the risk score calculation.
-
Distinguishes base, propagated, and resolution scores.
Values are
base,propagated, orresolution.
-
-
Observed roles assigned to the user.
-
An entity record representing a host, stored in the Entity Store latest index.
-
The time the entity record was last updated.
-
Asset metadata associated with the entity.
Additional properties are NOT allowed.
Hide asset attributes Show asset attributes object
-
Business unit the asset belongs to.
-
The criticality level of the asset.
Values are
low_impact,medium_impact,high_impact, orextreme_impact. -
Deployment environment (for example, production, staging).
-
Unique identifier for the asset.
-
Model name or number.
-
Human-readable asset name.
-
The owner of the asset.
-
Serial number of the asset.
-
Vendor or manufacturer.
-
-
Core entity fields shared across all entity types. The
entitynamespace is a root-level field in the Entity Store latest index.Additional properties are NOT allowed.
Hide entity attributes Show entity attributes object
-
Boolean flags describing characteristics of the entity.
Additional properties are NOT allowed.
Hide attributes attributes Show attributes attributes object
-
Boolean flags indicating observed behavioral signals.
Additional properties are NOT allowed.
-
Internal metadata attached to an entity by the engine that produced it.
Additional properties are NOT allowed.
-
Unique identifier for this entity.
-
Timestamps tracking the entity lifecycle.
Additional properties are NOT allowed.
-
Human-readable name of the entity.
-
Connections between this entity and other entities.
Additional properties are NOT allowed.
Hide relationships attributes Show relationships attributes object
-
Entity IDs that frequently access this entity.
-
Entity IDs this entity accesses frequently.
-
Entity IDs this entity accesses infrequently.
-
Entity IDs this entity communicates with.
-
Entity IDs that depend on this entity.
-
Entity IDs this entity depends on.
-
Entity IDs that own this entity.
-
Entity IDs owned by this entity.
-
Entity IDs that supervise this entity.
-
Entity IDs supervised by this entity.
-
-
Risk scoring information for the entity.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100.
-
-
The source that produced this entity record.
-
Optional sub-type classification for the entity.
-
The entity type.
-
-
Additional properties are NOT allowed.
-
Elastic Common Schema (ECS) host fields collected on the entity.
Additional properties are NOT allowed.
Hide host attributes Show host attributes object
-
Observed CPU architectures.
-
Observed host domains.
-
Core entity fields shared across all entity types. The
entitynamespace is a root-level field in the Entity Store latest index.Additional properties are NOT allowed.
Hide entity attributes Show entity attributes object
-
Boolean flags describing characteristics of the entity.
Additional properties are NOT allowed.
Hide attributes attributes Show attributes attributes object
-
Boolean flags indicating observed behavioral signals.
Additional properties are NOT allowed.
-
Internal metadata attached to an entity by the engine that produced it.
Additional properties are NOT allowed.
-
Unique identifier for this entity.
-
Timestamps tracking the entity lifecycle.
Additional properties are NOT allowed.
-
Human-readable name of the entity.
-
Connections between this entity and other entities.
Additional properties are NOT allowed.
Hide relationships attributes Show relationships attributes object
-
Entity IDs that frequently access this entity.
-
Entity IDs this entity accesses frequently.
-
Entity IDs this entity accesses infrequently.
-
Entity IDs this entity communicates with.
-
Entity IDs that depend on this entity.
-
Entity IDs this entity depends on.
-
Entity IDs that own this entity.
-
Entity IDs owned by this entity.
-
Entity IDs that supervise this entity.
-
Entity IDs supervised by this entity.
-
-
Risk scoring information for the entity.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100.
-
-
The source that produced this entity record.
-
Optional sub-type classification for the entity.
-
The entity type.
-
-
Observed hostnames.
-
Observed host IDs.
-
Observed IP addresses.
-
Observed MAC addresses.
-
Primary host name.
-
Elastic Common Schema (ECS) host.os fields collected on the entity latest index.
Additional properties are NOT allowed.
Hide os attributes Show os attributes object
-
Hide risk attributes Show risk attributes object
-
The time at which the risk score was calculated.
-
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100. -
Unique identifier for the scoring run that produced this document.
-
The number of risk input documents that contributed to the Category 1 score (
category_1_score). -
The contribution of Category 1 to the overall risk score (
calculated_score). Category 1 contains Detection Engine Alerts. -
The criticality level of the asset.
Values are
low_impact,medium_impact,high_impact, orextreme_impact. -
The identifier field defining this risk score. Coupled with
id_value, uniquely identifies the entity being scored. -
The identifier value defining this risk score. Coupled with
id_field, uniquely identifies the entity being scored. -
A list of the highest-risk documents contributing to this risk score. Useful for investigative purposes.
Hide inputs attributes Show inputs attributes object
A generic representation of a document contributing to a Risk Score.
-
The risk category of the risk input document.
-
A human-readable description of the risk input document.
-
The EUID of the entity within the graph that generated this alert.
-
The unique identifier (
_id) of the original source document -
The unique index (
_index) of the original source document -
The weighted risk score of the risk input document.
Minimum value is
0, maximum value is100. -
The @timestamp of the risk input document.
-
-
A list of modifiers that were applied to the risk score calculation.
-
Distinguishes base, propagated, and resolution scores.
Values are
base,propagated, orresolution.
-
-
Observed host types.
-
An entity record representing a service, stored in the Entity Store latest index.
-
The time the entity record was last updated.
-
Asset metadata associated with the entity.
Additional properties are NOT allowed.
Hide asset attributes Show asset attributes object
-
Business unit the asset belongs to.
-
The criticality level of the asset.
Values are
low_impact,medium_impact,high_impact, orextreme_impact. -
Deployment environment (for example, production, staging).
-
Unique identifier for the asset.
-
Model name or number.
-
Human-readable asset name.
-
The owner of the asset.
-
Serial number of the asset.
-
Vendor or manufacturer.
-
-
Core entity fields shared across all entity types. The
entitynamespace is a root-level field in the Entity Store latest index.Additional properties are NOT allowed.
Hide entity attributes Show entity attributes object
-
Boolean flags describing characteristics of the entity.
Additional properties are NOT allowed.
Hide attributes attributes Show attributes attributes object
-
Boolean flags indicating observed behavioral signals.
Additional properties are NOT allowed.
-
Internal metadata attached to an entity by the engine that produced it.
Additional properties are NOT allowed.
-
Unique identifier for this entity.
-
Timestamps tracking the entity lifecycle.
Additional properties are NOT allowed.
-
Human-readable name of the entity.
-
Connections between this entity and other entities.
Additional properties are NOT allowed.
Hide relationships attributes Show relationships attributes object
-
Entity IDs that frequently access this entity.
-
Entity IDs this entity accesses frequently.
-
Entity IDs this entity accesses infrequently.
-
Entity IDs this entity communicates with.
-
Entity IDs that depend on this entity.
-
Entity IDs this entity depends on.
-
Entity IDs that own this entity.
-
Entity IDs owned by this entity.
-
Entity IDs that supervise this entity.
-
Entity IDs supervised by this entity.
-
-
Risk scoring information for the entity.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100.
-
-
The source that produced this entity record.
-
Optional sub-type classification for the entity.
-
The entity type.
-
-
Additional properties are NOT allowed.
-
Elastic Common Schema (ECS) service fields collected on the entity.
Additional properties are NOT allowed.
Hide service attributes Show service attributes object
-
Core entity fields shared across all entity types. The
entitynamespace is a root-level field in the Entity Store latest index.Additional properties are NOT allowed.
Hide entity attributes Show entity attributes object
-
Boolean flags describing characteristics of the entity.
Additional properties are NOT allowed.
Hide attributes attributes Show attributes attributes object
-
Boolean flags indicating observed behavioral signals.
Additional properties are NOT allowed.
-
Internal metadata attached to an entity by the engine that produced it.
Additional properties are NOT allowed.
-
Unique identifier for this entity.
-
Timestamps tracking the entity lifecycle.
Additional properties are NOT allowed.
-
Human-readable name of the entity.
-
Connections between this entity and other entities.
Additional properties are NOT allowed.
Hide relationships attributes Show relationships attributes object
-
Entity IDs that frequently access this entity.
-
Entity IDs this entity accesses frequently.
-
Entity IDs this entity accesses infrequently.
-
Entity IDs this entity communicates with.
-
Entity IDs that depend on this entity.
-
Entity IDs this entity depends on.
-
Entity IDs that own this entity.
-
Entity IDs owned by this entity.
-
Entity IDs that supervise this entity.
-
Entity IDs supervised by this entity.
-
-
Risk scoring information for the entity.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100.
-
-
The source that produced this entity record.
-
Optional sub-type classification for the entity.
-
The entity type.
-
-
Primary service name.
-
Hide risk attributes Show risk attributes object
-
The time at which the risk score was calculated.
-
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100. -
Unique identifier for the scoring run that produced this document.
-
The number of risk input documents that contributed to the Category 1 score (
category_1_score). -
The contribution of Category 1 to the overall risk score (
calculated_score). Category 1 contains Detection Engine Alerts. -
The criticality level of the asset.
Values are
low_impact,medium_impact,high_impact, orextreme_impact. -
The identifier field defining this risk score. Coupled with
id_value, uniquely identifies the entity being scored. -
The identifier value defining this risk score. Coupled with
id_field, uniquely identifies the entity being scored. -
A list of the highest-risk documents contributing to this risk score. Useful for investigative purposes.
Hide inputs attributes Show inputs attributes object
A generic representation of a document contributing to a Risk Score.
-
The risk category of the risk input document.
-
A human-readable description of the risk input document.
-
The EUID of the entity within the graph that generated this alert.
-
The unique identifier (
_id) of the original source document -
The unique index (
_index) of the original source document -
The weighted risk score of the risk input document.
Minimum value is
0, maximum value is100. -
The @timestamp of the risk input document.
-
-
A list of modifiers that were applied to the risk score calculation.
-
Distinguishes base, propagated, and resolution scores.
Values are
base,propagated, orresolution.
-
-
A generic entity record. Maps only the entity and asset namespaces. Add additional field mappings here as needed.
-
The time the entity record was last updated.
-
Asset metadata associated with the entity.
Additional properties are NOT allowed.
Hide asset attributes Show asset attributes object
-
Business unit the asset belongs to.
-
The criticality level of the asset.
Values are
low_impact,medium_impact,high_impact, orextreme_impact. -
Deployment environment (for example, production, staging).
-
Unique identifier for the asset.
-
Model name or number.
-
Human-readable asset name.
-
The owner of the asset.
-
Serial number of the asset.
-
Vendor or manufacturer.
-
-
Core entity fields shared across all entity types. The
entitynamespace is a root-level field in the Entity Store latest index.Additional properties are NOT allowed.
Hide entity attributes Show entity attributes object
-
Boolean flags describing characteristics of the entity.
Additional properties are NOT allowed.
Hide attributes attributes Show attributes attributes object
-
Boolean flags indicating observed behavioral signals.
Additional properties are NOT allowed.
-
Internal metadata attached to an entity by the engine that produced it.
Additional properties are NOT allowed.
-
Unique identifier for this entity.
-
Timestamps tracking the entity lifecycle.
Additional properties are NOT allowed.
-
Human-readable name of the entity.
-
Connections between this entity and other entities.
Additional properties are NOT allowed.
Hide relationships attributes Show relationships attributes object
-
Entity IDs that frequently access this entity.
-
Entity IDs this entity accesses frequently.
-
Entity IDs this entity accesses infrequently.
-
Entity IDs this entity communicates with.
-
Entity IDs that depend on this entity.
-
Entity IDs this entity depends on.
-
Entity IDs that own this entity.
-
Entity IDs owned by this entity.
-
Entity IDs that supervise this entity.
-
Entity IDs supervised by this entity.
-
-
Risk scoring information for the entity.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100.
-
-
The source that produced this entity record.
-
Optional sub-type classification for the entity.
-
The entity type.
-
Responses
-
Entity updated or created
An entity record from the Entity Store. The
entitynamespace is a root-level field in the latest index, unlike source logs where it is nested underhost,user, orservice.One of: An entity record representing a user, stored in the Entity Store latest index.
Hide attributes Show attributes
-
The time the entity record was last updated.
-
Asset metadata associated with the entity.
Additional properties are NOT allowed.
Hide asset attributes Show asset attributes object
-
Business unit the asset belongs to.
-
The criticality level of the asset.
Values are
low_impact,medium_impact,high_impact, orextreme_impact. -
Deployment environment (for example, production, staging).
-
Unique identifier for the asset.
-
Model name or number.
-
Human-readable asset name.
-
The owner of the asset.
-
Serial number of the asset.
-
Vendor or manufacturer.
-
-
Core entity fields shared across all entity types. The
entitynamespace is a root-level field in the Entity Store latest index.Additional properties are NOT allowed.
Hide entity attributes Show entity attributes object
-
Boolean flags describing characteristics of the entity.
Additional properties are NOT allowed.
Hide attributes attributes Show attributes attributes object
-
Boolean flags indicating observed behavioral signals.
Additional properties are NOT allowed.
-
Internal metadata attached to an entity by the engine that produced it.
Additional properties are NOT allowed.
-
Unique identifier for this entity.
-
Timestamps tracking the entity lifecycle.
Additional properties are NOT allowed.
-
Human-readable name of the entity.
-
Connections between this entity and other entities.
Additional properties are NOT allowed.
Hide relationships attributes Show relationships attributes object
-
Entity IDs that frequently access this entity.
-
Entity IDs this entity accesses frequently.
-
Entity IDs this entity accesses infrequently.
-
Entity IDs this entity communicates with.
-
Entity IDs that depend on this entity.
-
Entity IDs this entity depends on.
-
Entity IDs that own this entity.
-
Entity IDs owned by this entity.
-
Entity IDs that supervise this entity.
-
Entity IDs supervised by this entity.
-
-
Risk scoring information for the entity.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100.
-
-
The source that produced this entity record.
-
Optional sub-type classification for the entity.
-
The entity type.
-
-
Additional properties are NOT allowed.
-
Elastic Common Schema (ECS) user fields collected on the entity.
Additional properties are NOT allowed.
Hide user attributes Show user attributes object
-
Observed user domains.
-
Observed email addresses.
-
Observed full names of the user.
-
Observed user hashes.
-
Observed user IDs.
-
Primary user name.
-
Hide risk attributes Show risk attributes object
-
The time at which the risk score was calculated.
-
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100. -
Unique identifier for the scoring run that produced this document.
-
The number of risk input documents that contributed to the Category 1 score (
category_1_score). -
The contribution of Category 1 to the overall risk score (
calculated_score). Category 1 contains Detection Engine Alerts. -
The criticality level of the asset.
Values are
low_impact,medium_impact,high_impact, orextreme_impact. -
The identifier field defining this risk score. Coupled with
id_value, uniquely identifies the entity being scored. -
The identifier value defining this risk score. Coupled with
id_field, uniquely identifies the entity being scored. -
A list of the highest-risk documents contributing to this risk score. Useful for investigative purposes.
Hide inputs attributes Show inputs attributes object
A generic representation of a document contributing to a Risk Score.
-
The risk category of the risk input document.
-
A human-readable description of the risk input document.
-
The EUID of the entity within the graph that generated this alert.
-
The unique identifier (
_id) of the original source document -
The unique index (
_index) of the original source document -
The weighted risk score of the risk input document.
Minimum value is
0, maximum value is100. -
The @timestamp of the risk input document.
-
-
A list of modifiers that were applied to the risk score calculation.
-
Distinguishes base, propagated, and resolution scores.
Values are
base,propagated, orresolution.
-
-
Observed roles assigned to the user.
-
An entity record representing a host, stored in the Entity Store latest index.
Hide attributes Show attributes
-
The time the entity record was last updated.
-
Asset metadata associated with the entity.
Additional properties are NOT allowed.
Hide asset attributes Show asset attributes object
-
Business unit the asset belongs to.
-
The criticality level of the asset.
Values are
low_impact,medium_impact,high_impact, orextreme_impact. -
Deployment environment (for example, production, staging).
-
Unique identifier for the asset.
-
Model name or number.
-
Human-readable asset name.
-
The owner of the asset.
-
Serial number of the asset.
-
Vendor or manufacturer.
-
-
Core entity fields shared across all entity types. The
entitynamespace is a root-level field in the Entity Store latest index.Additional properties are NOT allowed.
Hide entity attributes Show entity attributes object
-
Boolean flags describing characteristics of the entity.
Additional properties are NOT allowed.
Hide attributes attributes Show attributes attributes object
-
Boolean flags indicating observed behavioral signals.
Additional properties are NOT allowed.
-
Internal metadata attached to an entity by the engine that produced it.
Additional properties are NOT allowed.
-
Unique identifier for this entity.
-
Timestamps tracking the entity lifecycle.
Additional properties are NOT allowed.
-
Human-readable name of the entity.
-
Connections between this entity and other entities.
Additional properties are NOT allowed.
Hide relationships attributes Show relationships attributes object
-
Entity IDs that frequently access this entity.
-
Entity IDs this entity accesses frequently.
-
Entity IDs this entity accesses infrequently.
-
Entity IDs this entity communicates with.
-
Entity IDs that depend on this entity.
-
Entity IDs this entity depends on.
-
Entity IDs that own this entity.
-
Entity IDs owned by this entity.
-
Entity IDs that supervise this entity.
-
Entity IDs supervised by this entity.
-
-
Risk scoring information for the entity.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100.
-
-
The source that produced this entity record.
-
Optional sub-type classification for the entity.
-
The entity type.
-
-
Additional properties are NOT allowed.
-
Elastic Common Schema (ECS) host fields collected on the entity.
Additional properties are NOT allowed.
Hide host attributes Show host attributes object
-
Observed CPU architectures.
-
Observed host domains.
-
Core entity fields shared across all entity types. The
entitynamespace is a root-level field in the Entity Store latest index.Additional properties are NOT allowed.
Hide entity attributes Show entity attributes object
-
Boolean flags describing characteristics of the entity.
Additional properties are NOT allowed.
Hide attributes attributes Show attributes attributes object
-
Boolean flags indicating observed behavioral signals.
Additional properties are NOT allowed.
-
Internal metadata attached to an entity by the engine that produced it.
Additional properties are NOT allowed.
-
Unique identifier for this entity.
-
Timestamps tracking the entity lifecycle.
Additional properties are NOT allowed.
-
Human-readable name of the entity.
-
Connections between this entity and other entities.
Additional properties are NOT allowed.
Hide relationships attributes Show relationships attributes object
-
Entity IDs that frequently access this entity.
-
Entity IDs this entity accesses frequently.
-
Entity IDs this entity accesses infrequently.
-
Entity IDs this entity communicates with.
-
Entity IDs that depend on this entity.
-
Entity IDs this entity depends on.
-
Entity IDs that own this entity.
-
Entity IDs owned by this entity.
-
Entity IDs that supervise this entity.
-
Entity IDs supervised by this entity.
-
-
Risk scoring information for the entity.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100.
-
-
The source that produced this entity record.
-
Optional sub-type classification for the entity.
-
The entity type.
-
-
Observed hostnames.
-
Observed host IDs.
-
Observed IP addresses.
-
Observed MAC addresses.
-
Primary host name.
-
Elastic Common Schema (ECS) host.os fields collected on the entity latest index.
Additional properties are NOT allowed.
Hide os attributes Show os attributes object
-
Hide risk attributes Show risk attributes object
-
The time at which the risk score was calculated.
-
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100. -
Unique identifier for the scoring run that produced this document.
-
The number of risk input documents that contributed to the Category 1 score (
category_1_score). -
The contribution of Category 1 to the overall risk score (
calculated_score). Category 1 contains Detection Engine Alerts. -
The criticality level of the asset.
Values are
low_impact,medium_impact,high_impact, orextreme_impact. -
The identifier field defining this risk score. Coupled with
id_value, uniquely identifies the entity being scored. -
The identifier value defining this risk score. Coupled with
id_field, uniquely identifies the entity being scored. -
A list of the highest-risk documents contributing to this risk score. Useful for investigative purposes.
Hide inputs attributes Show inputs attributes object
A generic representation of a document contributing to a Risk Score.
-
The risk category of the risk input document.
-
A human-readable description of the risk input document.
-
The EUID of the entity within the graph that generated this alert.
-
The unique identifier (
_id) of the original source document -
The unique index (
_index) of the original source document -
The weighted risk score of the risk input document.
Minimum value is
0, maximum value is100. -
The @timestamp of the risk input document.
-
-
A list of modifiers that were applied to the risk score calculation.
-
Distinguishes base, propagated, and resolution scores.
Values are
base,propagated, orresolution.
-
-
Observed host types.
-
An entity record representing a service, stored in the Entity Store latest index.
Hide attributes Show attributes
-
The time the entity record was last updated.
-
Asset metadata associated with the entity.
Additional properties are NOT allowed.
Hide asset attributes Show asset attributes object
-
Business unit the asset belongs to.
-
The criticality level of the asset.
Values are
low_impact,medium_impact,high_impact, orextreme_impact. -
Deployment environment (for example, production, staging).
-
Unique identifier for the asset.
-
Model name or number.
-
Human-readable asset name.
-
The owner of the asset.
-
Serial number of the asset.
-
Vendor or manufacturer.
-
-
Core entity fields shared across all entity types. The
entitynamespace is a root-level field in the Entity Store latest index.Additional properties are NOT allowed.
Hide entity attributes Show entity attributes object
-
Boolean flags describing characteristics of the entity.
Additional properties are NOT allowed.
Hide attributes attributes Show attributes attributes object
-
Boolean flags indicating observed behavioral signals.
Additional properties are NOT allowed.
-
Internal metadata attached to an entity by the engine that produced it.
Additional properties are NOT allowed.
-
Unique identifier for this entity.
-
Timestamps tracking the entity lifecycle.
Additional properties are NOT allowed.
-
Human-readable name of the entity.
-
Connections between this entity and other entities.
Additional properties are NOT allowed.
Hide relationships attributes Show relationships attributes object
-
Entity IDs that frequently access this entity.
-
Entity IDs this entity accesses frequently.
-
Entity IDs this entity accesses infrequently.
-
Entity IDs this entity communicates with.
-
Entity IDs that depend on this entity.
-
Entity IDs this entity depends on.
-
Entity IDs that own this entity.
-
Entity IDs owned by this entity.
-
Entity IDs that supervise this entity.
-
Entity IDs supervised by this entity.
-
-
Risk scoring information for the entity.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100.
-
-
The source that produced this entity record.
-
Optional sub-type classification for the entity.
-
The entity type.
-
-
Additional properties are NOT allowed.
-
Elastic Common Schema (ECS) service fields collected on the entity.
Additional properties are NOT allowed.
Hide service attributes Show service attributes object
-
Core entity fields shared across all entity types. The
entitynamespace is a root-level field in the Entity Store latest index.Additional properties are NOT allowed.
Hide entity attributes Show entity attributes object
-
Boolean flags describing characteristics of the entity.
Additional properties are NOT allowed.
Hide attributes attributes Show attributes attributes object
-
Boolean flags indicating observed behavioral signals.
Additional properties are NOT allowed.
-
Internal metadata attached to an entity by the engine that produced it.
Additional properties are NOT allowed.
-
Unique identifier for this entity.
-
Timestamps tracking the entity lifecycle.
Additional properties are NOT allowed.
-
Human-readable name of the entity.
-
Connections between this entity and other entities.
Additional properties are NOT allowed.
Hide relationships attributes Show relationships attributes object
-
Entity IDs that frequently access this entity.
-
Entity IDs this entity accesses frequently.
-
Entity IDs this entity accesses infrequently.
-
Entity IDs this entity communicates with.
-
Entity IDs that depend on this entity.
-
Entity IDs this entity depends on.
-
Entity IDs that own this entity.
-
Entity IDs owned by this entity.
-
Entity IDs that supervise this entity.
-
Entity IDs supervised by this entity.
-
-
Risk scoring information for the entity.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100.
-
-
The source that produced this entity record.
-
Optional sub-type classification for the entity.
-
The entity type.
-
-
Primary service name.
-
Hide risk attributes Show risk attributes object
-
The time at which the risk score was calculated.
-
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100. -
Unique identifier for the scoring run that produced this document.
-
The number of risk input documents that contributed to the Category 1 score (
category_1_score). -
The contribution of Category 1 to the overall risk score (
calculated_score). Category 1 contains Detection Engine Alerts. -
The criticality level of the asset.
Values are
low_impact,medium_impact,high_impact, orextreme_impact. -
The identifier field defining this risk score. Coupled with
id_value, uniquely identifies the entity being scored. -
The identifier value defining this risk score. Coupled with
id_field, uniquely identifies the entity being scored. -
A list of the highest-risk documents contributing to this risk score. Useful for investigative purposes.
Hide inputs attributes Show inputs attributes object
A generic representation of a document contributing to a Risk Score.
-
The risk category of the risk input document.
-
A human-readable description of the risk input document.
-
The EUID of the entity within the graph that generated this alert.
-
The unique identifier (
_id) of the original source document -
The unique index (
_index) of the original source document -
The weighted risk score of the risk input document.
Minimum value is
0, maximum value is100. -
The @timestamp of the risk input document.
-
-
A list of modifiers that were applied to the risk score calculation.
-
Distinguishes base, propagated, and resolution scores.
Values are
base,propagated, orresolution.
-
-
A generic entity record. Maps only the
entityandassetnamespaces. Add additional field mappings here as needed.Hide attributes Show attributes
-
The time the entity record was last updated.
-
Asset metadata associated with the entity.
Additional properties are NOT allowed.
Hide asset attributes Show asset attributes object
-
Business unit the asset belongs to.
-
The criticality level of the asset.
Values are
low_impact,medium_impact,high_impact, orextreme_impact. -
Deployment environment (for example, production, staging).
-
Unique identifier for the asset.
-
Model name or number.
-
Human-readable asset name.
-
The owner of the asset.
-
Serial number of the asset.
-
Vendor or manufacturer.
-
-
Core entity fields shared across all entity types. The
entitynamespace is a root-level field in the Entity Store latest index.Additional properties are NOT allowed.
Hide entity attributes Show entity attributes object
-
Boolean flags describing characteristics of the entity.
Additional properties are NOT allowed.
Hide attributes attributes Show attributes attributes object
-
Boolean flags indicating observed behavioral signals.
Additional properties are NOT allowed.
-
Internal metadata attached to an entity by the engine that produced it.
Additional properties are NOT allowed.
-
Unique identifier for this entity.
-
Timestamps tracking the entity lifecycle.
Additional properties are NOT allowed.
-
Human-readable name of the entity.
-
Connections between this entity and other entities.
Additional properties are NOT allowed.
Hide relationships attributes Show relationships attributes object
-
Entity IDs that frequently access this entity.
-
Entity IDs this entity accesses frequently.
-
Entity IDs this entity accesses infrequently.
-
Entity IDs this entity communicates with.
-
Entity IDs that depend on this entity.
-
Entity IDs this entity depends on.
-
Entity IDs that own this entity.
-
Entity IDs owned by this entity.
-
Entity IDs that supervise this entity.
-
Entity IDs supervised by this entity.
-
-
Risk scoring information for the entity.
Additional properties are NOT allowed.
Hide risk attributes Show risk attributes object
-
Values are
Unknown,Low,Moderate,High, orCritical. -
The raw numeric value of the given entity's risk score.
-
The normalized numeric value of the given entity's risk score. Useful for comparing with other entities.
Minimum value is
0, maximum value is100.
-
-
The source that produced this entity record.
-
Optional sub-type classification for the entity.
-
The entity type.
-
-
-
Operation on a restricted field
-
Conflict. The entity was updated while another update was happening in ElasticSearch
-
Operation on an uninitialized Engine or in a cluster without CRUD API Enabled
curl \
--request PUT 'https://<KIBANA_URL>/api/entity_store/entities/user' \
--header "Authorization: $API_KEY" \
--header "Content-Type: application/json" \
--data '{"@timestamp":"2026-05-04T09:42:00Z","asset":{"business_unit":"string","criticality":"low_impact","environment":"string","id":"string","model":"string","name":"string","owner":"string","serial_number":"string","vendor":"string"},"entity":{"attributes":{"asset":true,"managed":true,"mfa_enabled":true,"privileged":true},"behaviors":{"brute_force_victim":true,"new_country_login":true,"used_usb_device":true},"EngineMetadata":{"Type":"string"},"id":"arn:aws:iam::123456789012:user/jane.doe","lifecycle":{"first_seen":"2026-05-04T09:42:00Z","last_activity":"2026-05-04T09:42:00Z","last_seen":"2026-05-04T09:42:00Z"},"name":"jane.doe","relationships":{"accessed_frequently_by":["string"],"accesses_frequently":["string"],"accesses_infrequently":["string"],"communicates_with":["string"],"dependent_of":["string"],"depends_on":["string"],"owned_by":["string"],"owns":["string"],"supervised_by":["string"],"supervises":["string"]},"risk":{"calculated_level":"Unknown","calculated_score":42.0,"calculated_score_norm":42.0},"source":"string","sub_type":"string","type":"user"},"event":{"ingested":"2026-05-04T09:42:00Z"},"user":{"domain":["string"],"email":["string"],"full_name":["string"],"hash":["string"],"id":["string"],"name":"string","risk":{"@timestamp":"2017-07-21T17:32:28Z","calculated_level":"Unknown","calculated_score":42.0,"calculated_score_norm":42.0,"calculation_run_id":"string","category_1_count":42,"category_1_score":42.0,"category_2_count":42,"category_2_score":42.0,"criticality_level":"low_impact","criticality_modifier":42.0,"id_field":"host.name","id_value":"example.host","inputs":[{"category":"category_1","contribution_score":42.0,"description":"Generated from Detection Engine Rule: Malware Prevention Alert","entity_id":"string","id":"91a93376a507e86cfbf282166275b89f9dbdb1f0be6c8103c6ff2909ca8e1a1c","index":".internal.alerts-security.alerts-default-000001","risk_score":42.0,"timestamp":"2017-07-21T17:32:28Z"}],"modifiers":[{"contribution":42.0,"metadata":{},"modifier_value":42.0,"subtype":"string","type":"string"}],"notes":["string"],"related_entities":[{"entity_id":"string","relationship_type":"string"}],"score_type":"base"},"roles":["string"]}}'