Body Required
-
description string | null
-
enabled boolean | null
-
name string
-
policy_ids array[string] | null
-
queries object
-
shards object
POST
/api/osquery/packs
curl \
--request POST https://localhost:5601/api/osquery/packs \
--header "Content-Type: application/json" \
--data '{"description":"string","enabled":true,"name":"string","policy_ids":["string"],"queries":{"additionalProperty1":{"ecs_mapping":{"additionalProperty1":{"field":"string","value":"string"},"additionalProperty2":{"field":"string","value":"string"}},"id":"string","platform":"string","query":"string","removed":true,"saved_query_id":"string","snapshot":true,"version":"string"},"additionalProperty2":{"ecs_mapping":{"additionalProperty1":{"field":"string","value":"string"},"additionalProperty2":{"field":"string","value":"string"}},"id":"string","platform":"string","query":"string","removed":true,"saved_query_id":"string","snapshot":true,"version":"string"}},"shards":{"additionalProperty1":42.0,"additionalProperty2":42.0}}'
Request examples
{
"description": "string",
"enabled": true,
"name": "string",
"policy_ids": [
"string"
],
"queries": {
"additionalProperty1": {
"ecs_mapping": {
"additionalProperty1": {
"field": "string",
"value": "string"
},
"additionalProperty2": {
"field": "string",
"value": "string"
}
},
"id": "string",
"platform": "string",
"query": "string",
"removed": true,
"saved_query_id": "string",
"snapshot": true,
"version": "string"
},
"additionalProperty2": {
"ecs_mapping": {
"additionalProperty1": {
"field": "string",
"value": "string"
},
"additionalProperty2": {
"field": "string",
"value": "string"
}
},
"id": "string",
"platform": "string",
"query": "string",
"removed": true,
"saved_query_id": "string",
"snapshot": true,
"version": "string"
}
},
"shards": {
"additionalProperty1": 42.0,
"additionalProperty2": 42.0
}
}
Response examples (200)
{}