Security Osquery API
Get live queries
Spaces method and path for this operation:
<div><span class="operation-verb get">get</span> <span class="operation-path">/s/{space_id}/api/osquery/live_queries</span></div>Refer to Spaces for more information.
Get a list of all live queries.
get/api/osquery/live_queries
Query parameters
kuerystring nullable
The kuery to filter the results by.
Example:agent.id: 16d7caf5-efd2-4212-9b62-73dafc91fa13
A KQL search string to filter live queries.
pageinteger nullable
The page number to return. The default is 1.
Example:1
The page number to return.
pageSizeinteger nullable
The number of results to return per page. The default is 20.
Example:20
The number of results to return per page.
sortstring nullable
The field that is used to sort the results.
Example:createdAt
The field to sort results by.
sortOrder'asc' | 'desc'
Specifies the sort order.
Example:desc
The sort order.
Response
Indicates a successful call.
Example response
{
"data": {
"items": [
{
"_source": {
"@timestamp": "2023-10-31T00:00:00Z",
"action_id": "3c42c847-eb30-4452-80e0-728584042334",
"agents": [
"16d7caf5-efd2-4212-9b62-73dafc91fa13"
],
"expiration": "2023-10-31T00:00:00Z",
"queries": [
{
"action_id": "609c4c66-ba3d-43fa-afdd-53e244577aa0",
"agents": [
"16d7caf5-efd2-4212-9b62-73dafc91fa13"
],
"ecs_mapping": {
"host.uptime": {
"field": "total_seconds"
}
},
"id": "6724a474-cbba-41ef-a1aa-66aebf0879e2",
"query": "select * from uptime;",
"saved_query_id": "42ba9c50-0cc5-11ed-aa1d-2b27890bc90d"
}
],
"result_counts": {
"error_agents": 0,
"responded_agents": 1,
"successful_agents": 1,
"total_rows": 42
},
"user_id": "elastic"
}
}
],
"total": 1
}
}