v53

latestOpenAPI 3.0.3raw.githubusercontent.com2026-08-076771,7565.2 MB
Security Exceptions API

Get an exception list summary

Spaces method and path for this operation:

<div><span class="operation-verb get">get</span>&nbsp;<span class="operation-path">/s/{space_id}/api/exception_lists/summary</span></div>

Refer to Spaces for more information.

Get a summary of the specified exception list.

get/api/exception_lists/summary

Query parameters

idstring nonempty

Exception list's identifier.

Example:9e5fc75a-a3da-46c5-96e3-a2ec59c6bb85

Exception list's identifier generated upon creation.

list_idstring nonempty

The exception list's human-readable string identifier.

For endpoint artifacts, use one of the following values:

  • endpoint_list: Elastic Endpoint exceptions list
  • endpoint_trusted_apps: Trusted applications list
  • endpoint_trusted_devices: Trusted devices list
  • endpoint_event_filters: Event filters list
  • endpoint_host_isolation_exceptions: Host isolation exceptions list
  • endpoint_blocklists: Blocklist
Example:simple_list

Exception list's human readable identifier.

namespace_type'agnostic' | 'single'

Determines whether the exception container is available in all Kibana spaces or just the space in which it is created, where:

  • single: Only available in the Kibana space in which it is created.
  • agnostic: Available in all Kibana spaces.

For endpoint artifacts, the namespace_type must always be agnostic. Space awareness for endpoint artifacts is enforced based on Elastic Defend policy assignments.

single returns summary for a list in the current space; agnostic for a space-agnostic list. Must line up with id / list_id used to look up the list.

filterstring
Example:exception-list-agnostic.attributes.tags:"policy:policy-1" OR exception-list-agnostic.attributes.tags:"policy:all"

Search filter clause

Response

Successful response

linuxinteger
macosinteger
totalinteger
windowsinteger