---
title: "Disable Attack Discovery schedule"
method: POST
path: "/api/attack_discovery/schedules/{id}/_disable"
tags: ["Security Attack discovery API"]
---

# Disable Attack Discovery schedule

`POST /api/attack_discovery/schedules/{id}/_disable`

**Spaces method and path for this operation:**

<div><span class="operation-verb post">post</span>&nbsp;<span class="operation-path">/s/{space_id}/api/attack_discovery/schedules/{id}/_disable</span></div>

Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information.

Disables an Attack Discovery schedule, preventing it from running according to its configured interval. The schedule configuration is preserved and can be re-enabled later. Any currently running executions will complete, but no new executions will be started.

## Path parameters

- `id` string, nonempty, required — A string that does not contain only whitespace characters.

## Response `200`

Successfully disabled Attack Discovery schedule, returning the schedule ID for confirmation

- object
  - `id` string, nonempty, required — A string that does not contain only whitespace characters.

## Other responses

- `400` — Bad Request response.

---

[API](https://skmtc.net/elastic/apis/kibana-apis.md) · [All operations](https://skmtc.net/elastic/apis/kibana-apis/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/elastic/kibana-apis/versions/531c9e2a7d23/schema)
