v53

latestOpenAPI 3.0.3raw.githubusercontent.com2026-08-076771,7565.2 MB
Security Osquery API

Get live query details

Spaces method and path for this operation:

<div><span class="operation-verb get">get</span>&nbsp;<span class="operation-path">/s/{space_id}/api/osquery/live_queries/{id}</span></div>

Refer to Spaces for more information.

Get the details of a live query using the query ID.

get/api/osquery/live_queries/{id}

Path parameters

idstring required

The ID of the live query result you want to retrieve.

Example:3c42c847-eb30-4452-80e0-728584042334

The ID of the live query.

Response

Indicates a successful call.

Example response

{
  "data": {
    "@timestamp": "2022-07-26T09:59:32.220Z",
    "action_id": "3c42c847-eb30-4452-80e0-728584042334",
    "agents": [
      "16d7caf5-efd2-4212-9b62-73dafc91fa13"
    ],
    "expiration": "2022-07-26T10:04:32.220Z",
    "queries": [
      {
        "action_id": "609c4c66-ba3d-43fa-afdd-53e244577aa0",
        "agents": [
          "16d7caf5-efd2-4212-9b62-73dafc91fa13"
        ],
        "docs": 0,
        "ecs_mapping": {
          "host.uptime": {
            "field": "total_seconds"
          }
        },
        "failed": 1,
        "id": "6724a474-cbba-41ef-a1aa-66aebf0879e2",
        "pending": 0,
        "query": "select * from uptime;",
        "responded": 1,
        "saved_query_id": "42ba9c50-0cc5-11ed-aa1d-2b27890bc90d",
        "status": "completed",
        "successful": 0
      }
    ],
    "status": "completed",
    "user_id": "elastic"
  }
}