Docs
  • Release notes
  • Troubleshoot
  • Reference
  1. Docs /
  2. Reference

Elastic Security reference

This section contains reference information for Elastic Security features, including:

  • Fields and object schemas
  • Endpoint command reference
  • Prebuilt detection rules reference

To learn more about Security features and how to get started, refer to Elastic Security. To interface with Elastic Security features, you can use these APIs.

Previous
ecctl version
Next
Fields and object schemas
  • View as Markdown
  • Report a docs issue
  • Edit this page
  • Learn how to contribute
Get started free
  • 14-day free trial
  • All features included
  • No setup required
  • Elastic fundamentals
  • Solutions and use cases
  • Manage data
  • Explore and analyze
  • Deploy and manage
  • Manage your Cloud account
  • Troubleshoot
  • Release notes
  • Reference
  • Extend and contribute
  • Contribute to the docs
  • Elasticsearch
    • Configuration
      • Circuit breaker settings
      • Auditing settings
      • Enrich settings
      • Cluster-level shard allocation and routing settings
      • Miscellaneous cluster settings
      • Cross-cluster replication settings
      • Discovery and cluster formation settings
      • Field data cache settings
      • Health Diagnostic settings
      • Index lifecycle management settings
      • Data stream lifecycle settings
      • Index management settings
      • Index recovery settings
      • Indexing buffer settings
      • Indexing pressure
      • Ingest settings
      • License settings
      • Local gateway
      • Machine learning settings
      • Inference settings
      • Monitoring settings
      • Node settings
      • Path settings
      • Networking settings
      • Node query cache settings
      • Remote cluster settings
      • Search settings
      • Security settings
      • Cluster state encryption
      • Shard request cache
      • Snapshot and restore settings
        • S3 repository
        • Azure repository
        • GCS repository
        • Shared file system repository
        • Read-only URL repository
        • Source-only repository
      • Transforms settings
      • Thread pool settings
      • Watcher settings
    • JVM settings
    • Built-in roles
    • Elasticsearch privileges
    • Columnar
    • Index settings
      • Serverless index settings
      • General
      • Shard allocation
        • Data tier allocation
        • Index recovery prioritization
        • Total shards per node
      • History retention
      • Index blocks
      • Mapping limit
      • Merge
      • Similarity
      • Slow log
      • Sorting
        • Use index sorting to speed up conjunctions
      • Store
        • Preloading data into the file system cache
      • Time series
      • Source settings
      • Translog
    • Index lifecycle actions
      • Allocate
      • Delete
      • Force merge
      • Migrate
      • Read only
      • Rollover
      • Downsample
      • Searchable snapshot
      • Set priority
      • Shrink
      • Unfollow
      • Wait for snapshot
    • REST APIs
      • API conventions
      • Common options
      • Compatibility
      • Guides and examples
        • Collapse search results
        • Create index from source
        • Understand the lifecycle status
        • Filter search results
        • Rescore search results
        • Find text structure API examples
        • Highlighting
          • Highlighting settings
          • Highlighting examples
          • How highlighters work internally
        • Analyze index disk usage
        • Optimistic concurrency control
        • Paginate search results
        • Query API key information
        • Reciprocal rank fusion
        • The refresh parameter
        • Reindex data stream
        • Reindex indices
        • Retrieve inner hits
        • Retrieve selected fields
        • Retrieve stored fields
        • Retrievers
          • kNN retriever
          • Linear retriever
          • Pinned retriever
          • Rescorer retriever
          • RRF retriever
          • Query rules retriever
          • Standard retriever
          • Text similarity re-ranker retriever
          • Diversify retriever
          • Examples
        • Search multiple data streams and indices
        • Profile search requests
        • Ranking evaluation
        • Search shard routing
        • Suggesters
        • Sort search results
        • Searching with query rules
        • The shard request cache
        • Term vectors API examples
        • Update By Query API
        • Update a document
        • Update cross-cluster API examples
        • Vector tile search API