v53

latestOpenAPI 3.0.3raw.githubusercontent.com2026-08-076771,7565.2 MB
Security Osquery API

Get live queries

Spaces method and path for this operation:

<div><span class="operation-verb get">get</span>&nbsp;<span class="operation-path">/s/{space_id}/api/osquery/live_queries</span></div>

Refer to Spaces for more information.

Get a list of all live queries.

get/api/osquery/live_queries

Query parameters

kuerystring nullable

The kuery to filter the results by.

Example:agent.id: 16d7caf5-efd2-4212-9b62-73dafc91fa13

A KQL search string to filter live queries.

pageinteger nullable

The page number to return. The default is 1.

Example:1

The page number to return.

pageSizeinteger nullable

The number of results to return per page. The default is 20.

Example:20

The number of results to return per page.

sortstring nullable

The field that is used to sort the results.

Example:createdAt

The field to sort results by.

sortOrder'asc' | 'desc'

Specifies the sort order.

Example:desc

The sort order.

Response

Indicates a successful call.

Example response

{
  "data": {
    "items": [
      {
        "_source": {
          "@timestamp": "2023-10-31T00:00:00Z",
          "action_id": "3c42c847-eb30-4452-80e0-728584042334",
          "agents": [
            "16d7caf5-efd2-4212-9b62-73dafc91fa13"
          ],
          "expiration": "2023-10-31T00:00:00Z",
          "queries": [
            {
              "action_id": "609c4c66-ba3d-43fa-afdd-53e244577aa0",
              "agents": [
                "16d7caf5-efd2-4212-9b62-73dafc91fa13"
              ],
              "ecs_mapping": {
                "host.uptime": {
                  "field": "total_seconds"
                }
              },
              "id": "6724a474-cbba-41ef-a1aa-66aebf0879e2",
              "query": "select * from uptime;",
              "saved_query_id": "42ba9c50-0cc5-11ed-aa1d-2b27890bc90d"
            }
          ],
          "result_counts": {
            "error_agents": 0,
            "responded_agents": 1,
            "successful_agents": 1,
            "total_rows": 42
          },
          "user_id": "elastic"
        }
      }
    ],
    "total": 1
  }
}