Update a saved query
Update a saved query using the query ID.
You cannot update a prebuilt saved query.
Body
Required
-
The saved query description.
-
Map osquery results columns or static values to Elastic Common Schema (ECS) fields
-
The ID of a saved query.
-
An interval, in seconds, on which to run the query.
-
Restricts the query to a specified platform. The default is all platforms. To specify multiple platforms, use commas. For example,
linux,darwin
. -
The SQL query you want to run.
-
Indicates whether the query is removed.
-
Indicates whether the query is a snapshot.
-
Uses the Osquery versions greater than or equal to the specified version string.
PUT
/api/osquery/saved_queries/{id}
curl \
--request PUT 'https://<KIBANA_URL>/api/osquery/saved_queries/3c42c847-eb30-4452-80e0-728584042334' \
--header "Authorization: $API_KEY" \
--header "Content-Type: application/json" \
--data '{"id":"updated_my_saved_query_name"}'
Request example
{
"id": "updated_my_saved_query_name"
}
Response examples (200)
{
"data": {}
}