获取异常项目编辑

使用其 iditem_id 字段检索异常项目。

请求 URL编辑

GET <kibana 主机>:<端口>/api/exception_lists/items

URL 查询参数编辑

URL 查询必须包含以下内容之一

  • id - GET /api/exception_lists/items?id=<id>
  • item_id - GET /api/exception_lists/items?item_id=<item_id>

示例请求编辑

检索 item_idglobal-allow-processes 的项目

GET api/exception_lists/items?item_id=global-allow-processes

响应代码编辑

200
指示成功调用。

响应负载编辑

{
  "_tags": [],
  "comments": [
    {
      "comment": "Allowed on all hosts.",
      "created_at": "2020-07-14T13:40:39.804Z",
      "created_by": "elastic"
    }
  ],
  "created_at": "2020-07-14T13:40:39.804Z",
  "created_by": "elastic",
  "description": "Global process allowlist",
  "entries": [
    {
      "field": "process.name",
      "operator": "included",
      "type": "match",
      "value": "housekeeping"
    }
  ],
  "id": "9b25aec0-c5d7-11ea-a3d8-a5b753aeeb9e",
  "item_id": "global-allow-processes",
  "list_id": "allowed-processes",
  "name": "Host-process global exclusion",
  "namespace_type": "single",
  "tags": [
    "global",
    "hosts",
    "processes"
  ],
  "tie_breaker_id": "28c6b069-8e39-4f9a-b93c-95e5a15b46c5",
  "type": "simple",
  "updated_at": "2020-07-14T13:40:39.980Z",
  "updated_by": "elastic"
}