Get an existing saved Timeline or Timeline template

GET /api/timeline/resolve

Query parameters

  • template_timeline_id string

    The ID of the template timeline to resolve

  • id string

    The ID of the timeline to resolve

Responses

  • 200 application/json

    The (template) Timeline has been found

    Hide response attributes Show response attributes object
    • alias_purpose string

      Values are savedObjectConversion or savedObjectImport.

    • alias_target_id string
    • outcome string Required

      Values are exactMatch, aliasMatch, or conflict.

    • timeline object | null Required
      Hide timeline attributes Show timeline attributes object | null
      • columns array[object] | null

        The Timeline's columns

        Hide columns attributes Show columns attributes object
        • aggregatable boolean | null
        • category string | null
        • columnHeaderType string | null
        • description string | null
        • example string | null
        • id string | null
        • indexes array[string] | null
        • name string | null
        • placeholder string | null
        • searchable boolean | null
        • type string | null
      • created number | null

        The time the Timeline was created, using a 13-digit Epoch timestamp.

      • createdBy string | null

        The user who created the Timeline.

      • dataProviders array[object] | null

        Object containing query clauses

        Hide dataProviders attributes Show dataProviders attributes object
        • and array[object] | null
          Hide and attributes Show and attributes object
          • enabled boolean | null
          • excluded boolean | null
          • id string | null
          • kqlQuery string | null
          • name string | null
          • queryMatch object | null
            Hide queryMatch attributes Show queryMatch attributes object | null
          • type string | null

            The type of data provider.

            Values are default or template.

        • enabled boolean | null
        • excluded boolean | null
        • id string | null
        • kqlQuery string | null
        • name string | null
        • queryMatch object | null
          Hide queryMatch attributes Show queryMatch attributes object | null
        • type string | null

          The type of data provider.

          Values are default or template.

      • dataViewId string | null

        ID of the Timeline's Data View

      • dateRange object | null

        The Timeline's search period.

        Hide dateRange attributes Show dateRange attributes object | null
      • description string | null

        The Timeline's description

      • eqlOptions object | null

        EQL query that is used in the correlation tab

        Hide eqlOptions attributes Show eqlOptions attributes object | null
      • eventType string | null Deprecated

        Event types displayed in the Timeline

      • excludedRowRendererIds array[string] | null

        A list of row renderers that should not be used when in Event renderers mode

        Values are alert, alerts, auditd, auditd_file, library, netflow, plain, registry, suricata, system, system_dns, system_endgame_process, system_file, system_fim, system_security_event, system_socket, threat_match, or zeek.

      • favorite array[object] | null

        Indicates when and who marked a Timeline as a favorite.

        Hide favorite attributes Show favorite attributes object
        • favoriteDate number | null
        • fullName string | null
        • userName string | null
      • filters array[object] | null

        A list of filters that should be applied to the query

        Hide filters attributes Show filters attributes object
        • exists string | null
        • match_all string | null
        • meta object | null
          Hide meta attributes Show meta attributes object | null
          • alias string | null
          • controlledBy string | null
          • disabled boolean | null
          • field string | null
          • formattedValue string | null
          • index string | null
          • key string | null
          • negate boolean | null
          • params string | null
          • type string | null
          • value string | null
        • missing string | null
        • query string | null
        • range string | null
        • script string | null
      • indexNames array[string] | null

        A list of index names to use in the query (e.g. when the default data view has been modified)

      • kqlMode string | null

        Indicates whether the KQL bar filters the query results or searches for additional results, where:

        • filter: filters query results
        • search: displays additional search results
      • kqlQuery object | null

        KQL bar query.

        Hide kqlQuery attribute Show kqlQuery attribute object | null
        • filterQuery object | null
          Hide filterQuery attributes Show filterQuery attributes object | null
          • kuery object | null
            Hide kuery attributes Show kuery attributes object | null
            • expression string | null
            • kind string | null
          • serializedQuery string | null
      • savedQueryId string | null

        The ID of the saved query that might be used in the Query tab

      • savedSearchId string | null

        The ID of the saved search that is used in the ES|QL tab

      • sort object | null | array[object]

        One of:

        Object indicating how rows are sorted in the Timeline's grid

        Hide attributes Show attributes object
        • columnId string | null
        • columnType string | null
        • sortDirection string | null
      • status string | null

        The status of the Timeline.

        Values are active, draft, or immutable.

      • templateTimelineId string | null

        A unique ID (UUID) for Timeline templates. For Timelines, the value is null.

      • templateTimelineVersion number | null

        Timeline template version number. For Timelines, the value is null.

      • timelineType string | null

        The type of Timeline.

        Values are default or template.

      • title string | null

        The Timeline's title.

      • updated number | null

        The last time the Timeline was updated, using a 13-digit Epoch timestamp

      • updatedBy string | null

        The user who last updated the Timeline

      • eventIdToNoteIds array[object] | null
        Hide eventIdToNoteIds attributes Show eventIdToNoteIds attributes object
        • created number | null

          The time the note was created, using a 13-digit Epoch timestamp.

        • createdBy string | null

          The user who created the note.

        • updated number | null

          The last time the note was updated, using a 13-digit Epoch timestamp

        • updatedBy string | null

          The user who last updated the note

        • eventId string | null

          The _id of the associated event for this note.

        • note string | null

          The text of the note

        • timelineId string Required

          The savedObjectId of the Timeline that this note is associated with

        • noteId string Required

          The savedObjectId of the note

        • version string Required

          The version of the note

      • noteIds array[string] | null
      • notes array[object] | null
        Hide notes attributes Show notes attributes object
        • created number | null

          The time the note was created, using a 13-digit Epoch timestamp.

        • createdBy string | null

          The user who created the note.

        • updated number | null

          The last time the note was updated, using a 13-digit Epoch timestamp

        • updatedBy string | null

          The user who last updated the note

        • eventId string | null

          The _id of the associated event for this note.

        • note string | null

          The text of the note

        • timelineId string Required

          The savedObjectId of the Timeline that this note is associated with

        • noteId string Required

          The savedObjectId of the note

        • version string Required

          The version of the note

      • pinnedEventIds array[string] | null
      • pinnedEventsSaveObject array[object] | null
        Hide pinnedEventsSaveObject attributes Show pinnedEventsSaveObject attributes object
        • created number | null

          The time the pinned event was created, using a 13-digit Epoch timestamp.

        • createdBy string | null

          The user who created the pinned event.

        • updated number | null

          The last time the pinned event was updated, using a 13-digit Epoch timestamp

        • updatedBy string | null

          The user who last updated the pinned event

        • eventId string Required

          The _id of the associated event for this pinned event.

        • timelineId string Required

          The savedObjectId of the timeline that this pinned event is associated with

        • pinnedEventId string Required

          The savedObjectId of this pinned event

        • version string Required

          The version of this pinned event

      • savedObjectId string Required
      • version string Required
  • 400

    The request is missing parameters

  • 404

    The (template) Timeline was not found

GET /api/timeline/resolve
curl \
 --request GET 'https://<KIBANA_URL>/api/timeline/resolve' \
 --header "Authorization: $API_KEY"