openapi: 3.2.0
info:
contact:
name: Kibana Team
description: 'The Kibana REST APIs enable you to manage resources such as connectors, data views, and saved objects.
The API calls are stateless.
Each request that you make happens in isolation from other calls and must include all of the necessary information for Kibana to fulfill the
request.
API requests return JSON output, which is a format that is machine-readable and works well for automation.
To interact with Kibana APIs, use the following operations:
- GET: Fetches the information.
- PATCH: Applies partial modifications to the existing information.
- POST: Adds new information.
- PUT: Updates the existing information.
- DELETE: Removes the information.
You can prepend any Kibana API endpoint with `kbn:` and run the request in **Dev Tools → Console**.
For example:
```
GET kbn:/api/data_views
```
For more information about the console, refer to [Run API requests](https://www.elastic.co/docs/explore-analyze/query-filter/tools/console).
NOTE: Access to internal Kibana API endpoints will be restricted in Kibana version 9.0. Please move any integrations to publicly documented APIs.
## Documentation source and versions
This documentation is derived from the `main` branch of the [kibana](https://github.com/elastic/kibana) repository.
It is provided under license [Attribution-NonCommercial-NoDerivatives 4.0 International](https://creativecommons.org/licenses/by-nc-nd/4.0/).
This documentation contains work-in-progress information for future Elastic Stack releases.
'
title: Kibana Fleet package policies API
version: ''
x-doc-license:
name: Attribution-NonCommercial-NoDerivatives 4.0 International
url: https://creativecommons.org/licenses/by-nc-nd/4.0/
x-feedbackLink:
label: Feedback
url: https://github.com/elastic/docs-content/issues/new?assignees=&labels=feedback%2Ccommunity&projects=&template=api-feedback.yaml&title=%5BFeedback%5D%3A+
servers:
- url: https://{kibana_url}
variables:
kibana_url:
default: localhost:5601
security:
- apiKeyAuth: []
- basicAuth: []
tags:
- name: Fleet package policies
description: 'Fleet package policies APIs enable you to manage Fleet package policies, including creating, updating, and deleting policies, performing bulk operations, and managing policy upgrades.
'
x-displayName: Fleet package policies
paths:
/api/fleet/package_policies:
get:
description: '**Spaces method and path for this operation:**
get /s/{space_id}/api/fleet/package_policies
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information.
List all package policies.'
operationId: get-fleet-package-policies
parameters:
- description: Page number
in: query
name: page
required: false
schema:
type: number
- description: Number of results per page
in: query
name: perPage
required: false
schema:
type: number
- description: Field to sort results by
in: query
name: sortField
required: false
schema:
type: string
- description: Sort order, ascending or descending
in: query
name: sortOrder
required: false
schema:
enum:
- desc
- asc
type: string
- description: When true, only show policies with available upgrades
in: query
name: showUpgradeable
required: false
schema:
type: boolean
- description: A KQL query string to filter results
in: query
name: kuery
required: false
schema:
type: string
- description: 'Format for the response: simplified or legacy'
in: query
name: format
required: false
schema:
enum:
- simplified
- legacy
type: string
- description: When true, include the agent count per package policy
in: query
name: withAgentCount
required: false
schema:
type: boolean
responses:
'200':
content:
application/json:
examples:
getPackagePoliciesExample:
description: List of package policies
value:
items:
- created_at: '2024-01-15T10:00:00.000Z'
enabled: true
id: package-policy-id-1
inputs: []
name: nginx-1
namespace: default
package:
name: nginx
title: Nginx
version: 1.20.0
policy_ids:
- agent-policy-id-1
updated_at: '2024-01-15T10:00:00.000Z'
page: 1
perPage: 20
total: 1
schema:
additionalProperties: false
type: object
properties:
items:
items:
$ref: '#/components/schemas/Kibana_HTTP_APIs_package_policy_response'
maxItems: 10000
type: array
page:
type: number
perPage:
type: number
total:
type: number
required:
- items
- total
- page
- perPage
description: Successful response
'400':
content:
application/json:
examples:
genericErrorResponseExample:
description: Example of a generic error response
value:
error: Bad Request
message: An error message describing what went wrong
statusCode: 400
schema:
additionalProperties: false
description: Generic Error
type: object
properties:
attributes: {}
error:
type: string
errorType:
type: string
message:
type: string
statusCode:
type: number
required:
- message
- attributes
description: Bad Request
summary: Get package policies
tags:
- Fleet package policies
x-metaTags:
- content: Kibana
name: product_name
post:
description: '**Spaces method and path for this operation:**
post /s/{space_id}/api/fleet/package_policies
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information.
Create a new package policy and assign it to an agent policy.'
operationId: post-fleet-package-policies
parameters:
- description: A required header to protect against CSRF attacks
in: header
name: kbn-xsrf
required: true
schema:
example: 'true'
type: string
- description: 'Format for the response: simplified or legacy'
in: query
name: format
required: false
schema:
enum:
- simplified
- legacy
type: string
requestBody:
content:
application/json:
examples:
postPackagePolicyRequestExample:
description: Create a new nginx package policy
value:
inputs: {}
name: nginx-1
namespace: default
package:
name: nginx
version: 1.20.0
policy_ids:
- agent-policy-id-1
schema:
anyOf:
- $ref: '#/components/schemas/Kibana_HTTP_APIs_create_package_policy_request'
- $ref: '#/components/schemas/Kibana_HTTP_APIs_simplified_create_package_policy_request'
description: You should use inputs as an object and not use the deprecated inputs array.
responses:
'200':
content:
application/json:
examples:
postPackagePolicyExample:
description: The created package policy
value:
item:
created_at: '2024-01-15T10:00:00.000Z'
enabled: true
id: package-policy-id-2
inputs: []
name: nginx-1
namespace: default
package:
name: nginx
title: Nginx
version: 1.20.0
policy_ids:
- agent-policy-id-1
updated_at: '2024-01-15T10:00:00.000Z'
schema:
$ref: '#/components/schemas/Kibana_HTTP_APIs_create_package_policy_response'
description: Successful response
'400':
content:
application/json:
examples:
genericErrorResponseExample:
description: Example of a generic error response
value:
error: Bad Request
message: An error message describing what went wrong
statusCode: 400
schema:
additionalProperties: false
description: Generic Error
type: object
properties:
attributes: {}
error:
type: string
errorType:
type: string
message:
type: string
statusCode:
type: number
required:
- message
- attributes
description: Bad Request
'409':
content:
application/json:
examples:
conflictExample:
description: A package policy with the same name already exists
value:
error: Conflict
message: An error message describing what went wrong
statusCode: 409
schema:
additionalProperties: false
description: Generic Error
type: object
properties:
attributes: {}
error:
type: string
errorType:
type: string
message:
type: string
statusCode:
type: number
required:
- message
- attributes
description: Conflict
summary: Create a package policy
tags:
- Fleet package policies
x-metaTags:
- content: Kibana
name: product_name
/api/fleet/package_policies/_bulk_get:
post:
description: '**Spaces method and path for this operation:**
post /s/{space_id}/api/fleet/package_policies/_bulk_get
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information.
Get multiple package policies by ID.'
operationId: post-fleet-package-policies-bulk-get
parameters:
- description: A required header to protect against CSRF attacks
in: header
name: kbn-xsrf
required: true
schema:
example: 'true'
type: string
- description: 'Format for the response: simplified or legacy'
in: query
name: format
required: false
schema:
enum:
- simplified
- legacy
type: string
requestBody:
content:
application/json:
examples:
postBulkGetPackagePoliciesRequestExample:
description: Retrieve multiple package policies by ID
value:
ids:
- package-policy-id-1
- package-policy-id-2
schema:
additionalProperties: false
type: object
properties:
ids:
description: list of package policy ids
items:
type: string
maxItems: 1000
type: array
ignoreMissing:
type: boolean
required:
- ids
responses:
'200':
content:
application/json:
examples:
postBulkGetPackagePoliciesExample:
description: The requested package policies
value:
items:
- created_at: '2024-01-15T10:00:00.000Z'
enabled: true
id: package-policy-id-1
inputs: []
name: nginx-1
namespace: default
package:
name: nginx
title: Nginx
version: 1.20.0
policy_ids:
- agent-policy-id-1
updated_at: '2024-01-15T10:00:00.000Z'
schema:
$ref: '#/components/schemas/Kibana_HTTP_APIs_bulk_get_package_policies_response'
description: Successful response
'400':
content:
application/json:
examples:
genericErrorResponseExample:
description: Example of a generic error response
value:
error: Bad Request
message: An error message describing what went wrong
statusCode: 400
schema:
additionalProperties: false
description: Generic Error
type: object
properties:
attributes: {}
error:
type: string
errorType:
type: string
message:
type: string
statusCode:
type: number
required:
- message
- attributes
description: Bad Request
'404':
content:
application/json:
examples:
notFoundExample:
description: One or more package policies were not found
value:
error: Not Found
message: Package policy package-policy-id-2 not found
statusCode: 404
schema:
additionalProperties: false
type: object
properties:
message:
type: string
required:
- message
description: Not Found
summary: Bulk get package policies
tags:
- Fleet package policies
x-metaTags:
- content: Kibana
name: product_name
/api/fleet/package_policies/{packagePolicyId}:
delete:
description: '**Spaces method and path for this operation:**
delete /s/{space_id}/api/fleet/package_policies/{packagePolicyId}
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information.
Delete a package policy by ID.
[Required authorization] Route required privileges: fleet-agent-policies-all AND integrations-all.'
operationId: delete-fleet-package-policies-packagepolicyid
parameters:
- description: A required header to protect against CSRF attacks
in: header
name: kbn-xsrf
required: true
schema:
example: 'true'
type: string
- description: The ID of the package policy
in: path
name: packagePolicyId
required: true
schema:
type: string
- description: When true, delete the package policy even if it is managed
in: query
name: force
required: false
schema:
type: boolean
responses:
'200':
content:
application/json:
examples:
deletePackagePolicyExample:
description: The package policy was successfully deleted
value:
id: package-policy-id-1
schema:
$ref: '#/components/schemas/Kibana_HTTP_APIs_delete_one_package_policy_response'
description: Successful response
'400':
content:
application/json:
examples:
genericErrorResponseExample:
description: Example of a generic error response
value:
error: Bad Request
message: An error message describing what went wrong
statusCode: 400
schema:
additionalProperties: false
description: Generic Error
type: object
properties:
attributes: {}
error:
type: string
errorType:
type: string
message:
type: string
statusCode:
type: number
required:
- message
- attributes
description: Bad Request
summary: Delete a package policy
tags:
- Fleet package policies
x-metaTags:
- content: Kibana
name: product_name
get:
description: '**Spaces method and path for this operation:**
get /s/{space_id}/api/fleet/package_policies/{packagePolicyId}
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information.
Get a package policy by ID.'
operationId: get-fleet-package-policies-packagepolicyid
parameters:
- description: The ID of the package policy
in: path
name: packagePolicyId
required: true
schema:
type: string
- description: 'Format for the response: simplified or legacy'
in: query
name: format
required: false
schema:
enum:
- simplified
- legacy
type: string
responses:
'200':
content:
application/json:
examples:
getPackagePolicyExample:
description: A package policy
value:
item:
created_at: '2024-01-15T10:00:00.000Z'
enabled: true
id: package-policy-id-1
inputs: []
name: nginx-1
namespace: default
package:
name: nginx
title: Nginx
version: 1.20.0
policy_ids:
- agent-policy-id-1
updated_at: '2024-01-15T10:00:00.000Z'
schema:
additionalProperties: false
type: object
properties:
item:
$ref: '#/components/schemas/Kibana_HTTP_APIs_package_policy_response'
required:
- item
description: Successful response
'400':
content:
application/json:
examples:
genericErrorResponseExample:
description: Example of a generic error response
value:
error: Bad Request
message: An error message describing what went wrong
statusCode: 400
schema:
additionalProperties: false
description: Generic Error
type: object
properties:
attributes: {}
error:
type: string
errorType:
type: string
message:
type: string
statusCode:
type: number
required:
- message
- attributes
description: Bad Request
'404':
content:
application/json:
examples:
notFoundExample:
description: No package policy was found with the given ID
value:
error: Not Found
message: Package policy package-policy-id-1 not found
statusCode: 404
schema:
additionalProperties: false
type: object
properties:
message:
type: string
required:
- message
description: Not Found
summary: Get a package policy
tags:
- Fleet package policies
x-metaTags:
- content: Kibana
name: product_name
put:
description: '**Spaces method and path for this operation:**
put /s/{space_id}/api/fleet/package_policies/{packagePolicyId}
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information.
Update a package policy by ID.'
operationId: put-fleet-package-policies-packagepolicyid
parameters:
- description: A required header to protect against CSRF attacks
in: header
name: kbn-xsrf
required: true
schema:
example: 'true'
type: string
- description: The ID of the package policy
in: path
name: packagePolicyId
required: true
schema:
type: string
- description: 'Format for the response: simplified or legacy'
in: query
name: format
required: false
schema:
enum:
- simplified
- legacy
type: string
requestBody:
content:
application/json:
examples:
putPackagePolicyRequestExample:
description: Update a package policy
value:
enabled: true
inputs: {}
name: nginx-1-updated
namespace: default
package:
name: nginx
version: 1.20.0
policy_ids:
- agent-policy-id-1
schema:
anyOf:
- $ref: '#/components/schemas/Kibana_HTTP_APIs_update_package_policy_request'
- $ref: '#/components/schemas/Kibana_HTTP_APIs_simplified_create_package_policy_request'
responses:
'200':
content:
application/json:
examples:
putPackagePolicyExample:
description: The updated package policy
value:
item:
created_at: '2024-01-15T10:00:00.000Z'
enabled: true
id: package-policy-id-1
inputs: []
name: nginx-1-updated
namespace: default
package:
name: nginx
title: Nginx
version: 1.20.0
policy_ids:
- agent-policy-id-1
updated_at: '2024-01-15T11:00:00.000Z'
schema:
additionalProperties: false
type: object
properties:
item:
$ref: '#/components/schemas/Kibana_HTTP_APIs_package_policy_response'
required:
- item
description: Successful response
'400':
content:
application/json:
examples:
genericErrorResponseExample:
description: Example of a generic error response
value:
error: Bad Request
message: An error message describing what went wrong
statusCode: 400
schema:
additionalProperties: false
description: Generic Error
type: object
properties:
attributes: {}
error:
type: string
errorType:
type: string
message:
type: string
statusCode:
type: number
required:
- message
- attributes
description: Bad Request
'403':
content:
application/json:
examples:
forbiddenExample:
description: The update is not authorized for this package
value:
error: Forbidden
message: An error message describing what went wrong
statusCode: 403
schema:
additionalProperties: false
description: Generic Error
type: object
properties:
attributes: {}
error:
type: string
errorType:
type: string
message:
type: string
statusCode:
type: number
required:
- message
- attributes
description: Forbidden
summary: Update a package policy
tags:
- Fleet package policies
x-metaTags:
- content: Kibana
name: product_name
/api/fleet/package_policies/delete:
post:
description: '**Spaces method and path for this operation:**
post /s/{space_id}/api/fleet/package_policies/delete
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information.
Delete multiple package policies by ID.
[Required authorization] Route required privileges: fleet-agent-policies-all AND integrations-all.'
operationId: post-fleet-package-policies-delete
parameters:
- description: A required header to protect against CSRF attacks
in: header
name: kbn-xsrf
required: true
schema:
example: 'true'
type: string
requestBody:
content:
application/json:
examples:
postDeletePackagePoliciesRequestExample:
description: Delete multiple package policies by ID
value:
packagePolicyIds:
- package-policy-id-1
- package-policy-id-2
schema:
$ref: '#/components/schemas/Kibana_HTTP_APIs_delete_package_policies_request'
responses:
'200':
content:
application/json:
examples:
postDeletePackagePoliciesExample:
description: Results of the bulk delete operation
value:
- id: package-policy-id-1
success: true
- id: package-policy-id-2
success: true
schema:
items:
$ref: '#/components/schemas/Kibana_HTTP_APIs_delete_package_policies_response_item'
maxItems: 10000
type: array
description: Successful response
'400':
content:
application/json:
examples:
genericErrorResponseExample:
description: Example of a generic error response
value:
error: Bad Request
message: An error message describing what went wrong
statusCode: 400
schema:
additionalProperties: false
description: Generic Error
type: object
properties:
attributes: {}
error:
type: string
errorType:
type: string
message:
type: string
statusCode:
type: number
required:
- message
- attributes
description: Bad Request
summary: Bulk delete package policies
tags:
- Fleet package policies
x-metaTags:
- content: Kibana
name: product_name
/api/fleet/package_policies/upgrade:
post:
description: '**Spaces method and path for this operation:**
post /s/{space_id}/api/fleet/package_policies/upgrade
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information.
Upgrade a package policy to a newer package version.
[Required authorization] Route required privileges: fleet-agent-policies-all AND integrations-all.'
operationId: post-fleet-package-policies-upgrade
parameters:
- description: A required header to protect against CSRF attacks
in: header
name: kbn-xsrf
required: true
schema:
example: 'true'
type: string
requestBody:
content:
application/json:
examples:
postUpgradePackagePoliciesRequestExample:
description: Upgrade package policies to the latest version
value:
packagePolicyIds:
- package-policy-id-1
schema:
$ref: '#/components/schemas/Kibana_HTTP_APIs_upgrade_package_policies_request'
responses:
'200':
content:
application/json:
examples:
postUpgradePackagePoliciesExample:
description: Results of the upgrade operation
value:
- id: package-policy-id-1
name: nginx-1
success: true
schema:
items:
$ref: '#/components/schemas/Kibana_HTTP_APIs_package_policy_status_response'
maxItems: 10000
type: array
description: Successful response
'400':
content:
application/json:
examples:
genericErrorResponseExample:
description: Example of a generic error response
value:
error: Bad Request
message: An error message describing what went wrong
statusCode: 400
schema:
additionalProperties: false
description: Generic Error
type: object
properties:
attributes: {}
error:
type: string
errorType:
type: string
message:
type: string
statusCode:
type: number
required:
- message
- attributes
description: Bad Request
summary: Upgrade a package policy
tags:
- Fleet package policies
x-metaTags:
- content: Kibana
name: product_name
/api/fleet/package_policies/upgrade/dryrun:
post:
description: '**Spaces method and path for this operation:**
post /s/{space_id}/api/fleet/package_policies/upgrade/dryrun
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information.
Preview the changes that would be applied by upgrading a package policy to a newer package version.
[Required authorization] Route required privileges: fleet-agent-policies-read AND integrations-read.'
operationId: post-fleet-package-policies-upgrade-dryrun
parameters:
- description: A required header to protect against CSRF attacks
in: header
name: kbn-xsrf
required: true
schema:
example: 'true'
type: string
requestBody:
content:
application/json:
examples:
postDryRunPackagePoliciesRequestExample:
description: Dry run an upgrade of a package policy
value:
packagePolicyIds:
- package-policy-id-1
schema:
$ref: '#/components/schemas/Kibana_HTTP_APIs_dry_run_package_policies_request'
responses:
'200':
content:
application/json:
examples:
postDryRunPackagePoliciesExample:
description: Preview of the package policy upgrade diff
value:
- diff:
- id: package-policy-id-1
name: nginx-1
package:
name: nginx
version: 1.20.0
- name: nginx-1
package:
name: nginx
version: 1.21.0
hasErrors: false
name: nginx-1
schema:
items:
additionalProperties: false
type: object
properties:
agent_diff:
items:
items:
additionalProperties: true
type: object
properties:
data_stream:
additionalProperties: true
type: object
properties:
namespace:
type: string
required:
- namespace
id:
type: string
meta:
additionalProperties: true
type: object
properties:
package:
additionalProperties: true
type: object
properties:
name:
type: string
version:
type: string
required:
- name
- version
required:
- package
name:
type: string
package_policy_id:
type: string
processors:
items:
additionalProperties: true
type: object
properties:
add_fields:
additionalProperties: true
type: object
properties:
fields:
additionalProperties:
anyOf:
- type: string
- type: number
type: object
target:
type: string
required:
- target
- fields
required:
- add_fields
maxItems: 10000
type: array
revision:
type: number
streams:
items:
additionalProperties: true
type: object
properties:
data_stream:
additionalProperties: true
type: object
properties:
dataset:
type: string
type:
type: string
required:
- dataset
id:
type: string
required:
- data_stream
maxItems: 10000
type: array
type:
type: string
use_output:
type: string
required:
- id
- name
- revision
- type
- data_stream
- use_output
- package_policy_id
maxItems: 10000
type: array
maxItems: 1
type: array
body:
additionalProperties: false
type: object
properties:
message:
type: string
required:
- message
diff:
items:
anyOf:
- $ref: '#/components/schemas/Kibana_HTTP_APIs_dry_run_package_policy_response'
- $ref: '#/components/schemas/Kibana_HTTP_APIs_dry_run_package_policy'
maxItems: 2
type: array
hasErrors:
type: boolean
name:
type: string
statusCode:
type: number
required:
- hasErrors
maxItems: 10000
type: array
description: Successful response
'400':
content:
application/json:
examples:
genericErrorResponseExample:
description: Example of a generic error response
value:
error: Bad Request
message: An error message describing what went wrong
statusCode: 400
schema:
additionalProperties: false
description: Generic Error
type: object
properties:
attributes: {}
error:
type: string
errorType:
type: string
message:
type: string
statusCode:
type: number
required:
- message
- attributes
description: Bad Request
summary: Dry run a package policy upgrade
tags:
- Fleet package policies
x-metaTags:
- content: Kibana
name: product_name
components:
schemas:
Kibana_HTTP_APIs_package_policy_input_deprecation_info:
additionalProperties: false
properties:
description:
maxLength: 4096
type: string
replaced_by:
additionalProperties:
maxLength: 1024
type: string
type: object
since:
maxLength: 50
type: string
required:
- description
title: package_policy_input_deprecation_info
type: object
Kibana_HTTP_APIs_delete_package_policies_response_item:
additionalProperties: false
properties:
body:
additionalProperties: false
type: object
properties:
message:
type: string
required:
- message
id:
type: string
name:
type: string
output_id:
type:
- string
- 'null'
package:
$ref: '#/components/schemas/Kibana_HTTP_APIs_package_policy_package'
policy_id:
deprecated: true
description: Use `policy_ids` instead
type:
- string
- 'null'
policy_ids:
items:
type: string
maxItems: 10000
type: array
statusCode:
type: number
success:
type: boolean
required:
- id
- success
- policy_ids
- package
title: delete_package_policies_response_item
type: object
Kibana_HTTP_APIs_create_package_policy_response:
additionalProperties: false
properties:
item:
$ref: '#/components/schemas/Kibana_HTTP_APIs_package_policy_response'
required:
- item
title: create_package_policy_response
type: object
Kibana_HTTP_APIs_delete_package_policies_request:
additionalProperties: false
properties:
force:
type: boolean
packagePolicyIds:
items:
type: string
maxItems: 1000
type: array
required:
- packagePolicyIds
title: delete_package_policies_request
type: object
Kibana_HTTP_APIs_package_policy_stream_deprecation_info:
additionalProperties: false
properties:
description:
maxLength: 4096
type: string
replaced_by:
additionalProperties:
maxLength: 1024
type: string
type: object
since:
maxLength: 50
type: string
required:
- description
title: package_policy_stream_deprecation_info
type: object
Kibana_HTTP_APIs_simplified_package_policy_stream_deprecation_info:
additionalProperties: false
properties:
description:
maxLength: 4096
type: string
replaced_by:
additionalProperties:
maxLength: 1024
type: string
type: object
since:
maxLength: 50
type: string
required:
- description
title: simplified_package_policy_stream_deprecation_info
type: object
Kibana_HTTP_APIs_upgrade_package_policies_request:
additionalProperties: false
properties:
packagePolicyIds:
items:
type: string
maxItems: 1000
type: array
required:
- packagePolicyIds
title: upgrade_package_policies_request
type: object
Kibana_HTTP_APIs_delete_one_package_policy_response:
additionalProperties: false
properties:
id:
type: string
required:
- id
title: delete_one_package_policy_response
type: object
Kibana_HTTP_APIs_dry_run_package_policy_response:
additionalProperties: false
properties:
additional_datastreams_permissions:
description: Additional data stream permissions that will be added to the agent policy.
items:
type: string
maxItems: 1000
type:
- array
- 'null'
agents:
type: number
cloud_connector_id:
description: ID of the cloud connector associated with this package policy.
type:
- string
- 'null'
cloud_connector_name:
description: Transient field for cloud connector name during creation.
maxLength: 255
minLength: 1
type:
- string
- 'null'
condition:
description: Agent condition expression to evaluate whether to apply this integration to its inputs.
maxLength: 10000
type:
- string
- 'null'
created_at:
type: string
created_by:
type: string
description:
description: Package policy description
type: string
elasticsearch:
additionalProperties: true
type: object
properties:
privileges:
additionalProperties: true
type: object
properties:
cluster:
items:
type: string
maxItems: 100
type: array
enabled:
type: boolean
global_data_tags:
items:
additionalProperties: false
type: object
properties:
name:
description: The name of the custom field. Cannot contain spaces.
type: string
value:
anyOf:
- type: string
- type: number
description: The value of the custom field.
required:
- name
- value
maxItems: 100
type:
- array
- 'null'
id:
maxLength: 255
type: string
inputs:
anyOf:
- items:
additionalProperties: false
type: object
properties:
compiled_input: {}
condition:
description: Agent condition expression to evaluate whether to apply this input.
maxLength: 10000
type:
- string
- 'null'
config:
additionalProperties:
additionalProperties: false
type: object
properties:
frozen:
type: boolean
type:
type: string
value: {}
required:
- value
description: Package variable (see integration documentation for more information)
type: object
deprecated:
$ref: '#/components/schemas/Kibana_HTTP_APIs_package_policy_input_deprecation_info'
enabled:
type: boolean
id:
type: string
keep_enabled:
type: boolean
migrate_from:
type: string
name:
type: string
policy_template:
type: string
streams:
items:
additionalProperties: false
type: object
properties:
compiled_stream: {}
condition:
description: Agent condition expression to evaluate whether to apply this stream.
maxLength: 10000
type:
- string
- 'null'
config:
additionalProperties:
additionalProperties: false
type: object
properties:
frozen:
type: boolean
type:
type: string
value: {}
required:
- value
description: Package variable (see integration documentation for more information)
type: object
data_stream:
additionalProperties: false
type: object
properties:
dataset:
type: string
elasticsearch:
additionalProperties: false
type: object
properties:
dynamic_dataset:
type: boolean
dynamic_namespace:
type: boolean
privileges:
additionalProperties: false
type: object
properties:
indices:
items:
type: string
maxItems: 100
type: array
type:
type: string
required:
- dataset
deprecated:
$ref: '#/components/schemas/Kibana_HTTP_APIs_package_policy_stream_deprecation_info'
enabled:
type: boolean
id:
type: string
keep_enabled:
type: boolean
migrate_from:
type: string
release:
enum:
- ga
- beta
- experimental
type: string
var_group_selections:
additionalProperties:
maxLength: 1024
type: string
description: Variable group selections. Maps var_group name to the selected option name within that group.
type: object
vars:
additionalProperties:
additionalProperties: false
type: object
properties:
frozen:
type: boolean
type:
type: string
value: {}
required:
- value
description: Package variable (see integration documentation for more information)
type: object
required:
- enabled
- data_stream
- compiled_stream
maxItems: 1000
type: array
type:
type: string
var_group_selections:
additionalProperties:
maxLength: 1024
type: string
description: Variable group selections. Maps var_group name to the selected option name within that group.
type: object
vars:
additionalProperties:
additionalProperties: false
type: object
properties:
frozen:
type: boolean
type:
type: string
value: {}
required:
- value
description: Package variable (see integration documentation for more information)
type: object
required:
- type
- enabled
- streams
- compiled_input
maxItems: 100
type: array
- additionalProperties:
additionalProperties: false
type: object
properties:
condition:
description: Agent condition expression to evaluate whether to apply this input.
maxLength: 10000
type:
- string
- 'null'
deprecated:
$ref: '#/components/schemas/Kibana_HTTP_APIs_simplified_package_policy_input_deprecation_info'
enabled:
description: Enable or disable that input. Defaults to `true` (enabled).
type: boolean
streams:
additionalProperties:
additionalProperties: false
type: object
properties:
condition:
description: Agent condition expression to evaluate whether to apply this stream.
maxLength: 10000
type:
- string
- 'null'
deprecated:
$ref: '#/components/schemas/Kibana_HTTP_APIs_simplified_package_policy_stream_deprecation_info'
enabled:
description: Enable or disable that stream. Defaults to `true` (enabled).
type: boolean
var_group_selections:
additionalProperties:
maxLength: 1024
type: string
description: Variable group selections. Maps var_group name to the selected option name within that group.
type: object
vars:
additionalProperties:
anyOf:
- maxLength: 10000
type: string
- type: number
- type: boolean
- items:
maxLength: 10000
type: string
maxItems: 100
type: array
- items:
type: number
maxItems: 100
type: array
- additionalProperties: false
type: object
properties:
id:
maxLength: 255
type: string
isSecretRef:
type: boolean
required:
- id
- isSecretRef
default: null
description: Input/stream level variable. Refer to the integration documentation for more information.
type: object
description: Input streams. Refer to the integration documentation to know which streams are available.
type: object
vars:
additionalProperties:
anyOf:
- maxLength: 10000
type: string
- type: number
- type: boolean
- items:
maxLength: 10000
type: string
maxItems: 100
type: array
- items:
type: number
maxItems: 100
type: array
- additionalProperties: false
type: object
properties:
id:
maxLength: 255
type: string
isSecretRef:
type: boolean
required:
- id
- isSecretRef
default: null
description: Input/stream level variable. Refer to the integration documentation for more information.
type: object
description: Package policy inputs. Refer to the integration documentation to know which inputs are available.
type: object
description: Package policy inputs.
is_managed:
type: boolean
name:
description: Unique name for the package policy.
type: string
namespace:
description: The package policy namespace. Leave blank to inherit the agent policy's namespace.
maxLength: 100
type: string
output_id:
type:
- string
- 'null'
overrides:
additionalProperties: false
description: Override settings that are defined in the package policy. The override option should be used only in unusual circumstances and not as a routine procedure.
type:
- object
- 'null'
properties:
inputs:
additionalProperties: {}
type: object
package:
$ref: '#/components/schemas/Kibana_HTTP_APIs_package_policy_package'
package_agent_version_condition:
type: string
policy_id:
deprecated: true
description: ID of the agent policy which the package policy will be added to.
type:
- string
- 'null'
policy_ids:
items:
description: IDs of the agent policies that the package policy will be added to.
type: string
maxItems: 1000
type: array
revision:
description: Package policy revision.
type: number
secret_references:
items:
additionalProperties: false
type: object
properties:
id:
type: string
required:
- id
maxItems: 1000
type: array
spaceIds:
items:
type: string
maxItems: 100
type: array
supports_agentless:
description: Indicates whether the package policy belongs to an agentless agent policy.
type:
- boolean
- 'null'
supports_cloud_connector:
description: Indicates whether the package policy supports cloud connectors.
type:
- boolean
- 'null'
updated_at:
type: string
updated_by:
type: string
var_group_selections:
additionalProperties:
maxLength: 1024
type: string
description: Variable group selections. Maps var_group name to the selected option name within that group.
type: object
vars:
anyOf:
- additionalProperties:
additionalProperties: false
type: object
properties:
frozen:
type: boolean
type:
type: string
value: {}
required:
- value
description: Package variable (see integration documentation for more information)
type: object
- additionalProperties:
anyOf:
- maxLength: 10000
type: string
- type: number
- type: boolean
- items:
maxLength: 10000
type: string
maxItems: 100
type: array
- items:
type: number
maxItems: 100
type: array
- additionalProperties: false
type: object
properties:
id:
maxLength: 255
type: string
isSecretRef:
type: boolean
required:
- id
- isSecretRef
default: null
description: Input/stream level variable. Refer to the integration documentation for more information.
type: object
description: Package level variable.
version:
description: Package policy ES version.
type: string
required:
- name
- enabled
- inputs
- revision
- updated_at
- updated_by
- created_at
- created_by
title: dry_run_package_policy_response
type: object
Kibana_HTTP_APIs_package_policy_package:
additionalProperties: false
properties:
experimental_data_stream_features:
items:
additionalProperties: false
type: object
properties:
data_stream:
maxLength: 1024
type: string
features:
additionalProperties: false
type: object
properties:
doc_value_only_numeric:
type: boolean
doc_value_only_other:
type: boolean
synthetic_source:
type: boolean
tsdb:
type: boolean
required:
- data_stream
- features
maxItems: 100
type: array
fips_compatible:
type: boolean
name:
description: Package name
maxLength: 255
type: string
requires_root:
type: boolean
title:
maxLength: 255
type: string
version:
description: Package version
maxLength: 50
type: string
required:
- name
- version
title: package_policy_package
type: object
Kibana_HTTP_APIs_simplified_package_policy_input_deprecation_info:
additionalProperties: false
properties:
description:
maxLength: 4096
type: string
replaced_by:
additionalProperties:
maxLength: 1024
type: string
type: object
since:
maxLength: 50
type: string
required:
- description
title: simplified_package_policy_input_deprecation_info
type: object
Kibana_HTTP_APIs_update_package_policy_request:
additionalProperties: false
properties:
additional_datastreams_permissions:
description: Additional data stream permissions that will be added to the agent policy.
items:
type: string
maxItems: 1000
type:
- array
- 'null'
cloud_connector_id:
description: ID of the cloud connector associated with this package policy.
type:
- string
- 'null'
cloud_connector_name:
description: Transient field for cloud connector name during creation.
maxLength: 255
minLength: 1
type:
- string
- 'null'
condition:
description: Agent condition expression to evaluate whether to apply this integration to its inputs.
maxLength: 10000
type:
- string
- 'null'
description:
description: Package policy description
type: string
enabled:
type: boolean
force:
type: boolean
global_data_tags:
items:
additionalProperties: false
type: object
properties:
name:
description: The name of the custom field. Cannot contain spaces.
type: string
value:
anyOf:
- type: string
- type: number
description: The value of the custom field.
required:
- name
- value
maxItems: 100
type:
- array
- 'null'
inputs:
items:
additionalProperties: false
type: object
properties:
condition:
description: Agent condition expression to evaluate whether to apply this input.
maxLength: 10000
type:
- string
- 'null'
config:
additionalProperties:
additionalProperties: false
type: object
properties:
frozen:
type: boolean
type:
type: string
value: {}
required:
- value
description: Package variable (see integration documentation for more information)
type: object
deprecated:
$ref: '#/components/schemas/Kibana_HTTP_APIs_package_policy_input_deprecation_info'
enabled:
type: boolean
id:
type: string
keep_enabled:
type: boolean
migrate_from:
type: string
name:
type: string
policy_template:
type: string
streams:
items:
additionalProperties: false
type: object
properties:
compiled_stream: {}
condition:
description: Agent condition expression to evaluate whether to apply this stream.
maxLength: 10000
type:
- string
- 'null'
config:
additionalProperties:
additionalProperties: false
type: object
properties:
frozen:
type: boolean
type:
type: string
value: {}
required:
- value
description: Package variable (see integration documentation for more information)
type: object
data_stream:
additionalProperties: false
type: object
properties:
dataset:
type: string
elasticsearch:
additionalProperties: false
type: object
properties:
dynamic_dataset:
type: boolean
dynamic_namespace:
type: boolean
privileges:
additionalProperties: false
type: object
properties:
indices:
items:
type: string
maxItems: 100
type: array
type:
type: string
required:
- dataset
deprecated:
$ref: '#/components/schemas/Kibana_HTTP_APIs_package_policy_stream_deprecation_info'
enabled:
type: boolean
id:
type: string
keep_enabled:
type: boolean
migrate_from:
type: string
release:
enum:
- ga
- beta
- experimental
type: string
var_group_selections:
additionalProperties:
maxLength: 1024
type: string
description: Variable group selections. Maps var_group name to the selected option name within that group.
type: object
vars:
additionalProperties:
additionalProperties: false
type: object
properties:
frozen:
type: boolean
type:
type: string
value: {}
required:
- value
description: Package variable (see integration documentation for more information)
type: object
required:
- enabled
- data_stream
- compiled_stream
maxItems: 1000
type: array
type:
type: string
var_group_selections:
additionalProperties:
maxLength: 1024
type: string
description: Variable group selections. Maps var_group name to the selected option name within that group.
type: object
vars:
additionalProperties:
additionalProperties: false
type: object
properties:
frozen:
type: boolean
type:
type: string
value: {}
required:
- value
description: Package variable (see integration documentation for more information)
type: object
required:
- type
- enabled
maxItems: 1000
type: array
is_managed:
type: boolean
name:
type: string
namespace:
description: The package policy namespace. Leave blank to inherit the agent policy's namespace.
maxLength: 100
type: string
output_id:
type:
- string
- 'null'
overrides:
additionalProperties: false
description: Override settings that are defined in the package policy. The override option should be used only in unusual circumstances and not as a routine procedure.
type:
- object
- 'null'
properties:
inputs:
additionalProperties: {}
type: object
package:
$ref: '#/components/schemas/Kibana_HTTP_APIs_package_policy_package'
package_agent_version_condition:
type: string
policy_id:
deprecated: true
description: ID of the agent policy which the package policy will be added to.
type:
- string
- 'null'
policy_ids:
items:
description: IDs of the agent policies that the package policy will be added to.
type: string
maxItems: 1000
type: array
spaceIds:
items:
type: string
maxItems: 100
type: array
supports_agentless:
description: Indicates whether the package policy belongs to an agentless agent policy.
type:
- boolean
- 'null'
supports_cloud_connector:
description: Indicates whether the package policy supports cloud connectors.
type:
- boolean
- 'null'
var_group_selections:
additionalProperties:
maxLength: 1024
type: string
description: Variable group selections. Maps var_group name to the selected option name within that group.
type: object
vars:
additionalProperties:
additionalProperties: false
type: object
properties:
frozen:
type: boolean
type:
type: string
value: {}
required:
- value
description: Package variable (see integration documentation for more information)
type: object
version:
type: string
title: update_package_policy_request
type: object
Kibana_HTTP_APIs_simplified_create_package_policy_request:
additionalProperties: false
properties:
additional_datastreams_permissions:
description: Additional data stream permissions that will be added to the agent policy.
items:
maxLength: 256
type: string
maxItems: 100
type:
- array
- 'null'
condition:
description: Agent condition expression to evaluate whether to apply this integration to its inputs.
maxLength: 10000
type:
- string
- 'null'
create_dataset_templates:
description: When true, install dedicated index templates for streams with a custom data_stream.dataset. Defaults to true for input packages, false for integration packages.
type: boolean
description:
description: Policy description.
maxLength: 2048
type: string
force:
description: Force package policy creation even if the package is not verified, or if the agent policy is managed.
type: boolean
id:
description: Policy unique identifier.
maxLength: 255
type: string
inputs:
additionalProperties:
additionalProperties: false
type: object
properties:
condition:
description: Agent condition expression to evaluate whether to apply this input.
maxLength: 10000
type:
- string
- 'null'
deprecated:
$ref: '#/components/schemas/Kibana_HTTP_APIs_simplified_package_policy_input_deprecation_info'
enabled:
description: Enable or disable that input. Defaults to `true` (enabled).
type: boolean
streams:
additionalProperties:
additionalProperties: false
type: object
properties:
condition:
description: Agent condition expression to evaluate whether to apply this stream.
maxLength: 10000
type:
- string
- 'null'
deprecated:
$ref: '#/components/schemas/Kibana_HTTP_APIs_simplified_package_policy_stream_deprecation_info'
enabled:
description: Enable or disable that stream. Defaults to `true` (enabled).
type: boolean
var_group_selections:
additionalProperties:
maxLength: 1024
type: string
description: Variable group selections. Maps var_group name to the selected option name within that group.
type: object
vars:
additionalProperties:
anyOf:
- maxLength: 10000
type: string
- type: number
- type: boolean
- items:
maxLength: 10000
type: string
maxItems: 100
type: array
- items:
type: number
maxItems: 100
type: array
- additionalProperties: false
type: object
properties:
id:
maxLength: 255
type: string
isSecretRef:
type: boolean
required:
- id
- isSecretRef
default: null
description: Input/stream level variable. Refer to the integration documentation for more information.
type: object
description: Input streams. Refer to the integration documentation to know which streams are available.
type: object
vars:
additionalProperties:
anyOf:
- maxLength: 10000
type: string
- type: number
- type: boolean
- items:
maxLength: 10000
type: string
maxItems: 100
type: array
- items:
type: number
maxItems: 100
type: array
- additionalProperties: false
type: object
properties:
id:
maxLength: 255
type: string
isSecretRef:
type: boolean
required:
- id
- isSecretRef
default: null
description: Input/stream level variable. Refer to the integration documentation for more information.
type: object
description: Package policy inputs. Refer to the integration documentation to know which inputs are available.
type: object
name:
description: Unique name for the policy.
maxLength: 255
type: string
namespace:
description: Policy namespace. When not specified, it inherits the agent policy namespace.
maxLength: 100
type: string
output_id:
maxLength: 255
type:
- string
- 'null'
package:
$ref: '#/components/schemas/Kibana_HTTP_APIs_package_policy_package'
policy_id:
deprecated: true
description: Deprecated. Use policy_ids instead.
maxLength: 255
type:
- string
- 'null'
policy_ids:
description: IDs of the agent policies that the package policy will be added to.
items:
maxLength: 255
type: string
maxItems: 1000
type: array
supports_agentless:
deprecated: true
description: Indicates whether the package policy belongs to an agentless agent policy. Deprecated in favor of the Fleet managed integrations API.
type:
- boolean
- 'null'
var_group_selections:
additionalProperties:
maxLength: 1024
type: string
description: Variable group selections. Maps var_group name to the selected option name within that group.
type: object
vars:
additionalProperties:
anyOf:
- maxLength: 10000
type: string
- type: number
- type: boolean
- items:
maxLength: 10000
type: string
maxItems: 100
type: array
- items:
type: number
maxItems: 100
type: array
- additionalProperties: false
type: object
properties:
id:
maxLength: 255
type: string
isSecretRef:
type: boolean
required:
- id
- isSecretRef
default: null
description: Input/stream level variable. Refer to the integration documentation for more information.
type: object
required:
- name
- package
title: simplified_create_package_policy_request
type: object
Kibana_HTTP_APIs_dry_run_package_policies_request:
additionalProperties: false
properties:
packagePolicyIds:
items:
type: string
maxItems: 1000
type: array
packageVersion:
type: string
required:
- packagePolicyIds
title: dry_run_package_policies_request
type: object
Kibana_HTTP_APIs_package_policy_response:
additionalProperties: false
properties:
additional_datastreams_permissions:
description: Additional data stream permissions that will be added to the agent policy.
items:
type: string
maxItems: 1000
type:
- array
- 'null'
agents:
type: number
cloud_connector_id:
description: ID of the cloud connector associated with this package policy.
type:
- string
- 'null'
cloud_connector_name:
description: Transient field for cloud connector name during creation.
maxLength: 255
minLength: 1
type:
- string
- 'null'
condition:
description: Agent condition expression to evaluate whether to apply this integration to its inputs.
maxLength: 10000
type:
- string
- 'null'
created_at:
type: string
created_by:
type: string
description:
description: Package policy description
type: string
elasticsearch:
additionalProperties: true
type: object
properties:
privileges:
additionalProperties: true
type: object
properties:
cluster:
items:
type: string
maxItems: 100
type: array
enabled:
type: boolean
global_data_tags:
items:
additionalProperties: false
type: object
properties:
name:
description: The name of the custom field. Cannot contain spaces.
type: string
value:
anyOf:
- type: string
- type: number
description: The value of the custom field.
required:
- name
- value
maxItems: 100
type:
- array
- 'null'
id:
description: Package policy unique identifier.
type: string
inputs:
anyOf:
- items:
additionalProperties: false
type: object
properties:
compiled_input: {}
condition:
description: Agent condition expression to evaluate whether to apply this input.
maxLength: 10000
type:
- string
- 'null'
config:
additionalProperties:
additionalProperties: false
type: object
properties:
frozen:
type: boolean
type:
type: string
value: {}
required:
- value
description: Package variable (see integration documentation for more information)
type: object
deprecated:
$ref: '#/components/schemas/Kibana_HTTP_APIs_package_policy_input_deprecation_info'
enabled:
type: boolean
id:
type: string
keep_enabled:
type: boolean
migrate_from:
type: string
name:
type: string
policy_template:
type: string
streams:
items:
additionalProperties: false
type: object
properties:
compiled_stream: {}
condition:
description: Agent condition expression to evaluate whether to apply this stream.
maxLength: 10000
type:
- string
- 'null'
config:
additionalProperties:
additionalProperties: false
type: object
properties:
frozen:
type: boolean
type:
type: string
value: {}
required:
- value
description: Package variable (see integration documentation for more information)
type: object
data_stream:
additionalProperties: false
type: object
properties:
dataset:
type: string
elasticsearch:
additionalProperties: false
type: object
properties:
dynamic_dataset:
type: boolean
dynamic_namespace:
type: boolean
privileges:
additionalProperties: false
type: object
properties:
indices:
items:
type: string
maxItems: 100
type: array
type:
type: string
required:
- dataset
deprecated:
$ref: '#/components/schemas/Kibana_HTTP_APIs_package_policy_stream_deprecation_info'
enabled:
type: boolean
id:
type: string
keep_enabled:
type: boolean
migrate_from:
type: string
release:
enum:
- ga
- beta
- experimental
type: string
var_group_selections:
additionalProperties:
maxLength: 1024
type: string
description: Variable group selections. Maps var_group name to the selected option name within that group.
type: object
vars:
additionalProperties:
additionalProperties: false
type: object
properties:
frozen:
type: boolean
type:
type: string
value: {}
required:
- value
description: Package variable (see integration documentation for more information)
type: object
required:
- enabled
- data_stream
- compiled_stream
maxItems: 1000
type: array
type:
type: string
var_group_selections:
additionalProperties:
maxLength: 1024
type: string
description: Variable group selections. Maps var_group name to the selected option name within that group.
type: object
vars:
additionalProperties:
additionalProperties: false
type: object
properties:
frozen:
type: boolean
type:
type: string
value: {}
required:
- value
description: Package variable (see integration documentation for more information)
type: object
required:
- type
- enabled
- streams
- compiled_input
maxItems: 100
type: array
- additionalProperties:
additionalProperties: false
type: object
properties:
condition:
description: Agent condition expression to evaluate whether to apply this input.
maxLength: 10000
type:
- string
- 'null'
deprecated:
$ref: '#/components/schemas/Kibana_HTTP_APIs_simplified_package_policy_input_deprecation_info'
enabled:
description: Enable or disable that input. Defaults to `true` (enabled).
type: boolean
streams:
additionalProperties:
additionalProperties: false
type: object
properties:
condition:
description: Agent condition expression to evaluate whether to apply this stream.
maxLength: 10000
type:
- string
- 'null'
deprecated:
$ref: '#/components/schemas/Kibana_HTTP_APIs_simplified_package_policy_stream_deprecation_info'
enabled:
description: Enable or disable that stream. Defaults to `true` (enabled).
type: boolean
var_group_selections:
additionalProperties:
maxLength: 1024
type: string
description: Variable group selections. Maps var_group name to the selected option name within that group.
type: object
vars:
additionalProperties:
anyOf:
- maxLength: 10000
type: string
- type: number
- type: boolean
- items:
maxLength: 10000
type: string
maxItems: 100
type: array
- items:
type: number
maxItems: 100
type: array
- additionalProperties: false
type: object
properties:
id:
maxLength: 255
type: string
isSecretRef:
type: boolean
required:
- id
- isSecretRef
default: null
description: Input/stream level variable. Refer to the integration documentation for more information.
type: object
description: Input streams. Refer to the integration documentation to know which streams are available.
type: object
vars:
additionalProperties:
anyOf:
- maxLength: 10000
type: string
- type: number
- type: boolean
- items:
maxLength: 10000
type: string
maxItems: 100
type: array
- items:
type: number
maxItems: 100
type: array
- additionalProperties: false
type: object
properties:
id:
maxLength: 255
type: string
isSecretRef:
type: boolean
required:
- id
- isSecretRef
default: null
description: Input/stream level variable. Refer to the integration documentation for more information.
type: object
description: Package policy inputs. Refer to the integration documentation to know which inputs are available.
type: object
description: Package policy inputs.
is_managed:
type: boolean
name:
description: Unique name for the package policy.
type: string
namespace:
description: The package policy namespace. Leave blank to inherit the agent policy's namespace.
maxLength: 100
type: string
output_id:
type:
- string
- 'null'
overrides:
additionalProperties: false
description: Override settings that are defined in the package policy. The override option should be used only in unusual circumstances and not as a routine procedure.
type:
- object
- 'null'
properties:
inputs:
additionalProperties: {}
type: object
package:
$ref: '#/components/schemas/Kibana_HTTP_APIs_package_policy_package'
package_agent_version_condition:
type: string
policy_id:
deprecated: true
description: ID of the agent policy which the package policy will be added to.
type:
- string
- 'null'
policy_ids:
items:
description: IDs of the agent policies that the package policy will be added to.
type: string
maxItems: 1000
type: array
revision:
description: Package policy revision.
type: number
secret_references:
items:
additionalProperties: false
type: object
properties:
id:
type: string
required:
- id
maxItems: 1000
type: array
spaceIds:
items:
type: string
maxItems: 100
type: array
supports_agentless:
description: Indicates whether the package policy belongs to an agentless agent policy.
type:
- boolean
- 'null'
supports_cloud_connector:
description: Indicates whether the package policy supports cloud connectors.
type:
- boolean
- 'null'
updated_at:
type: string
updated_by:
type: string
var_group_selections:
additionalProperties:
maxLength: 1024
type: string
description: Variable group selections. Maps var_group name to the selected option name within that group.
type: object
vars:
anyOf:
- additionalProperties:
additionalProperties: false
type: object
properties:
frozen:
type: boolean
type:
type: string
value: {}
required:
- value
description: Package variable (see integration documentation for more information)
type: object
- additionalProperties:
anyOf:
- maxLength: 10000
type: string
- type: number
- type: boolean
- items:
maxLength: 10000
type: string
maxItems: 100
type: array
- items:
type: number
maxItems: 100
type: array
- additionalProperties: false
type: object
properties:
id:
maxLength: 255
type: string
isSecretRef:
type: boolean
required:
- id
- isSecretRef
default: null
description: Input/stream level variable. Refer to the integration documentation for more information.
type: object
description: Package level variable.
version:
description: Package policy ES version.
type: string
required:
- name
- enabled
- inputs
- id
- revision
- updated_at
- updated_by
- created_at
- created_by
title: package_policy_response
type: object
Kibana_HTTP_APIs_dry_run_package_policy:
additionalProperties: true
properties:
additional_datastreams_permissions:
description: Additional data stream permissions that will be added to the agent policy.
items:
type: string
maxItems: 1000
type:
- array
- 'null'
cloud_connector_id:
description: ID of the cloud connector associated with this package policy.
type:
- string
- 'null'
cloud_connector_name:
description: Transient field for cloud connector name during creation.
maxLength: 255
minLength: 1
type:
- string
- 'null'
condition:
description: Agent condition expression to evaluate whether to apply this integration to its inputs.
maxLength: 10000
type:
- string
- 'null'
created_at:
type: string
created_by:
type: string
description:
description: Package policy description
type: string
elasticsearch:
additionalProperties: true
type: object
properties:
privileges:
additionalProperties: true
type: object
properties:
cluster:
items:
type: string
maxItems: 100
type: array
enabled:
type: boolean
errors:
items:
additionalProperties: false
type: object
properties:
key:
type: string
message:
type: string
required:
- message
maxItems: 10
type: array
force:
type: boolean
global_data_tags:
items:
additionalProperties: false
type: object
properties:
name:
description: The name of the custom field. Cannot contain spaces.
type: string
value:
anyOf:
- type: string
- type: number
description: The value of the custom field.
required:
- name
- value
maxItems: 100
type:
- array
- 'null'
id:
maxLength: 255
type: string
inputs:
items:
additionalProperties: false
type: object
properties:
compiled_input: {}
condition:
description: Agent condition expression to evaluate whether to apply this input.
maxLength: 10000
type:
- string
- 'null'
config:
additionalProperties:
additionalProperties: false
type: object
properties:
frozen:
type: boolean
type:
type: string
value: {}
required:
- value
description: Package variable (see integration documentation for more information)
type: object
deprecated:
$ref: '#/components/schemas/Kibana_HTTP_APIs_package_policy_input_deprecation_info'
enabled:
type: boolean
id:
type: string
keep_enabled:
type: boolean
migrate_from:
type: string
name:
type: string
policy_template:
type: string
streams:
items:
additionalProperties: false
type: object
properties:
compiled_stream: {}
condition:
description: Agent condition expression to evaluate whether to apply this stream.
maxLength: 10000
type:
- string
- 'null'
config:
additionalProperties:
additionalProperties: false
type: object
properties:
frozen:
type: boolean
type:
type: string
value: {}
required:
- value
description: Package variable (see integration documentation for more information)
type: object
data_stream:
additionalProperties: false
type: object
properties:
dataset:
type: string
elasticsearch:
additionalProperties: false
type: object
properties:
dynamic_dataset:
type: boolean
dynamic_namespace:
type: boolean
privileges:
additionalProperties: false
type: object
properties:
indices:
items:
type: string
maxItems: 100
type: array
type:
type: string
required:
- dataset
deprecated:
$ref: '#/components/schemas/Kibana_HTTP_APIs_package_policy_stream_deprecation_info'
enabled:
type: boolean
id:
type: string
keep_enabled:
type: boolean
migrate_from:
type: string
release:
enum:
- ga
- beta
- experimental
type: string
var_group_selections:
additionalProperties:
maxLength: 1024
type: string
description: Variable group selections. Maps var_group name to the selected option name within that group.
type: object
vars:
additionalProperties:
additionalProperties: false
type: object
properties:
frozen:
type: boolean
type:
type: string
value: {}
required:
- value
description: Package variable (see integration documentation for more information)
type: object
required:
- enabled
- data_stream
- compiled_stream
maxItems: 1000
type: array
type:
type: string
var_group_selections:
additionalProperties:
maxLength: 1024
type: string
description: Variable group selections. Maps var_group name to the selected option name within that group.
type: object
vars:
additionalProperties:
additionalProperties: false
type: object
properties:
frozen:
type: boolean
type:
type: string
value: {}
required:
- value
description: Package variable (see integration documentation for more information)
type: object
required:
- type
- enabled
- streams
- compiled_input
maxItems: 100
type: array
is_managed:
type: boolean
missingVars:
items:
type: string
maxItems: 100
type: array
name:
description: Unique name for the package policy.
type: string
namespace:
description: The package policy namespace. Leave blank to inherit the agent policy's namespace.
maxLength: 100
type: string
output_id:
type:
- string
- 'null'
overrides:
additionalProperties: false
description: Override settings that are defined in the package policy. The override option should be used only in unusual circumstances and not as a routine procedure.
type:
- object
- 'null'
properties:
inputs:
additionalProperties: {}
type: object
package:
$ref: '#/components/schemas/Kibana_HTTP_APIs_package_policy_package'
package_agent_version_condition:
type: string
policy_id:
deprecated: true
description: ID of the agent policy which the package policy will be added to.
type:
- string
- 'null'
policy_ids:
items:
description: IDs of the agent policies that the package policy will be added to.
type: string
maxItems: 1000
type: array
revision:
type: number
secret_references:
items:
additionalProperties: false
type: object
properties:
id:
type: string
required:
- id
maxItems: 1000
type: array
supports_agentless:
description: Indicates whether the package policy belongs to an agentless agent policy.
type:
- boolean
- 'null'
supports_cloud_connector:
description: Indicates whether the package policy supports cloud connectors.
type:
- boolean
- 'null'
updated_at:
type: string
updated_by:
type: string
var_group_selections:
additionalProperties:
maxLength: 1024
type: string
description: Variable group selections. Maps var_group name to the selected option name within that group.
type: object
vars:
additionalProperties:
additionalProperties: false
type: object
properties:
frozen:
type: boolean
type:
type: string
value: {}
required:
- value
description: Package variable (see integration documentation for more information)
type: object
version:
description: Package policy ES version.
type: string
required:
- name
- enabled
- inputs
title: dry_run_package_policy
type: object
Kibana_HTTP_APIs_package_policy_status_response:
additionalProperties: false
properties:
body:
additionalProperties: false
type: object
properties:
message:
type: string
required:
- message
id:
type: string
name:
type: string
statusCode:
type: number
success:
type: boolean
required:
- id
- success
title: package_policy_status_response
type: object
Kibana_HTTP_APIs_bulk_get_package_policies_response:
additionalProperties: false
properties:
items:
items:
$ref: '#/components/schemas/Kibana_HTTP_APIs_package_policy_response'
maxItems: 10000
type: array
required:
- items
title: bulk_get_package_policies_response
type: object
Kibana_HTTP_APIs_create_package_policy_request:
additionalProperties: false
properties:
additional_datastreams_permissions:
description: Additional data stream permissions that will be added to the agent policy.
items:
type: string
maxItems: 1000
type:
- array
- 'null'
cloud_connector_id:
description: ID of the cloud connector associated with this package policy.
type:
- string
- 'null'
cloud_connector_name:
description: Transient field for cloud connector name during creation.
maxLength: 255
minLength: 1
type:
- string
- 'null'
condition:
description: Agent condition expression to evaluate whether to apply this integration to its inputs.
maxLength: 10000
type:
- string
- 'null'
create_dataset_templates:
description: When true, install dedicated index templates for streams with a custom data_stream.dataset. Defaults to true for input packages, false for integration packages.
type: boolean
description:
description: Package policy description
type: string
enabled:
type: boolean
force:
description: Force package policy creation even if the package is not verified, or if the agent policy is managed.
type: boolean
global_data_tags:
items:
additionalProperties: false
type: object
properties:
name:
description: The name of the custom field. Cannot contain spaces.
type: string
value:
anyOf:
- type: string
- type: number
description: The value of the custom field.
required:
- name
- value
maxItems: 100
type:
- array
- 'null'
id:
description: Package policy unique identifier
type: string
inputs:
items:
additionalProperties: false
type: object
properties:
condition:
description: Agent condition expression to evaluate whether to apply this input.
maxLength: 10000
type:
- string
- 'null'
config:
additionalProperties:
additionalProperties: false
type: object
properties:
frozen:
type: boolean
type:
type: string
value: {}
required:
- value
description: Package variable (see integration documentation for more information)
type: object
deprecated:
$ref: '#/components/schemas/Kibana_HTTP_APIs_package_policy_input_deprecation_info'
enabled:
type: boolean
id:
type: string
keep_enabled:
type: boolean
migrate_from:
type: string
name:
type: string
policy_template:
type: string
streams:
items:
additionalProperties: false
type: object
properties:
compiled_stream: {}
condition:
description: Agent condition expression to evaluate whether to apply this stream.
maxLength: 10000
type:
- string
- 'null'
config:
additionalProperties:
additionalProperties: false
type: object
properties:
frozen:
type: boolean
type:
type: string
value: {}
required:
- value
description: Package variable (see integration documentation for more information)
type: object
data_stream:
additionalProperties: false
type: object
properties:
dataset:
type: string
elasticsearch:
additionalProperties: false
type: object
properties:
dynamic_dataset:
type: boolean
dynamic_namespace:
type: boolean
privileges:
additionalProperties: false
type: object
properties:
indices:
items:
type: string
maxItems: 100
type: array
type:
type: string
required:
- dataset
deprecated:
$ref: '#/components/schemas/Kibana_HTTP_APIs_package_policy_stream_deprecation_info'
enabled:
type: boolean
id:
type: string
keep_enabled:
type: boolean
migrate_from:
type: string
release:
enum:
- ga
- beta
- experimental
type: string
var_group_selections:
additionalProperties:
maxLength: 1024
type: string
description: Variable group selections. Maps var_group name to the selected option name within that group.
type: object
vars:
additionalProperties:
additionalProperties: false
type: object
properties:
frozen:
type: boolean
type:
type: string
value: {}
required:
- value
description: Package variable (see integration documentation for more information)
type: object
required:
- enabled
- data_stream
- compiled_stream
maxItems: 1000
type: array
type:
type: string
var_group_selections:
additionalProperties:
maxLength: 1024
type: string
description: Variable group selections. Maps var_group name to the selected option name within that group.
type: object
vars:
additionalProperties:
additionalProperties: false
type: object
properties:
frozen:
type: boolean
type:
type: string
value: {}
required:
- value
description: Package variable (see integration documentation for more information)
type: object
required:
- type
- enabled
maxItems: 1000
type: array
is_managed:
type: boolean
name:
description: Unique name for the package policy.
type: string
namespace:
description: The package policy namespace. Leave blank to inherit the agent policy's namespace.
maxLength: 100
type: string
output_id:
type:
- string
- 'null'
overrides:
additionalProperties: false
description: Override settings that are defined in the package policy. The override option should be used only in unusual circumstances and not as a routine procedure.
type:
- object
- 'null'
properties:
inputs:
additionalProperties: {}
type: object
package:
$ref: '#/components/schemas/Kibana_HTTP_APIs_package_policy_package'
package_agent_version_condition:
type: string
policy_id:
deprecated: true
description: ID of the agent policy which the package policy will be added to.
type:
- string
- 'null'
policy_ids:
items:
description: IDs of the agent policies that the package policy will be added to.
type: string
maxItems: 1000
type: array
spaceIds:
items:
type: string
maxItems: 100
type: array
supports_agentless:
deprecated: true
description: Indicates whether the package policy belongs to an agentless agent policy. Deprecated in favor of the Fleet managed integrations API.
type:
- boolean
- 'null'
supports_cloud_connector:
description: Indicates whether the package policy supports cloud connectors.
type:
- boolean
- 'null'
var_group_selections:
additionalProperties:
maxLength: 1024
type: string
description: Variable group selections. Maps var_group name to the selected option name within that group.
type: object
vars:
additionalProperties:
additionalProperties: false
type: object
properties:
frozen:
type: boolean
type:
type: string
value: {}
required:
- value
description: Package variable (see integration documentation for more information)
type: object
required:
- name
- inputs
title: create_package_policy_request
type: object
securitySchemes:
apiKeyAuth:
description: 'These APIs use key-based authentication. You must create an API key and use the encoded value in the request header. For example: `Authorization: ApiKey base64AccessApiKey`
'
in: header
name: Authorization
type: apiKey
basicAuth:
scheme: basic
type: http
x-topics:
- title: Kibana spaces
content: "Spaces enable you to organize your dashboards and other saved objects into meaningful categories.\nYou can use the default space or create your own spaces.\n\nTo run APIs in non-default spaces, you must add `s/{space_id}/` to the path.\nFor example:\n\n```bash\ncurl -X GET \"http://${KIBANA_URL}/s/marketing/api/data_views\" \\\n -H \"Authorization: ApiKey ${API_KEY}\"\n```\n\nIf you use the Kibana console to send API requests, it automatically adds the appropriate space identifier.\n\nTo learn more, check out [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces).\n"