Tool to find and/or aggregate detection alerts in Kibana. Use this to retrieve a list of alerts, optionally filtering them with a query and performing aggregations.
aggsobjectDefines aggregations to be performed. Refer to Elasticsearch aggregation documentation.
sizeintegerNumber of alerts to return. Defaults to a server-side limit if not specified.
queryobjectElasticsearch query DSL to filter alerts. Supports match_all, term, match, bool, range, exists, wildcard, and other Elasticsearch query types. Defaults to match_all if not specified.
runtime_mappingsobjectDefines runtime fields. Refer to Elasticsearch runtime fields documentation.
dataRequiredData from the action execution
errorstringError if any occurred during the execution of the action
successfulRequiredbooleanWhether or not the action execution was successful or not
API key connection. Risk level 2 of 5.
Free Action
No published Skills explicitly reference this Action yet.