Update a saved query
Update a saved query using the query ID.
You cannot update a prebuilt saved query.
Body Required
-
description string | null
-
ecs_mapping object | null
-
id string | null
-
interval string
-
platform string | null
-
query string
-
removed boolean | null
-
snapshot boolean | null
-
version string | null
PUT /api/osquery/saved_queries/{id}
curl \
-X PUT https://localhost:5601/api/osquery/saved_queries/{id} \
-H "Content-Type: application/json; Elastic-Api-Version=2023-10-31"
Request examples
{
"description": "string",
"ecs_mapping": {
"additionalProperty1": {
"field": "string",
"value": "string"
},
"additionalProperty2": {
"field": "string",
"value": "string"
}
},
"id": "string",
"interval": "string",
"platform": "string",
"query": "string",
"removed": true,
"snapshot": true,
"version": "string"
}
Response examples (200)
{}