Delete a saved Osquery query by its saved object ID. Use this to remove a specific Osquery saved query from Kibana. IMPORTANT: This action requires the 'saved_object_id' (UUID format), not the custom 'id' field. You can obtain the saved_object_id by listing queries first or from…
idRequiredstringThe saved object ID of the Osquery query to delete. This is the 'saved_object_id' field returned when creating or listing queries, NOT the custom 'id' field. Example format: 'a85f2478-23ca-4835-b56f-d6e065114534'
dataRequiredData from the action execution
errorstringError if any occurred during the execution of the action
successfulRequiredbooleanWhether or not the action execution was successful or not
API key connection. Risk level 2 of 5.
Free Action
No published Skills explicitly reference this Action yet.