|
@@ -84,6 +84,11 @@ include::{docdir}/rest-api/common-parms.asciidoc[tag=index-ignore-unavailable]
|
|
[[eql-search-api-request-body]]
|
|
[[eql-search-api-request-body]]
|
|
==== {api-request-body-title}
|
|
==== {api-request-body-title}
|
|
|
|
|
|
|
|
+`case_sensitive`::
|
|
|
|
+(Optional, boolean)
|
|
|
|
+If `true`, matching for the <<eql-search-api-request-query-param,EQL query>> is
|
|
|
|
+case sensitive. Defaults to `false`.
|
|
|
|
+
|
|
`event_category_field`::
|
|
`event_category_field`::
|
|
(Required*, string)
|
|
(Required*, string)
|
|
Field containing the event classification, such as `process`, `file`, or
|
|
Field containing the event classification, such as `process`, `file`, or
|
|
@@ -102,6 +107,7 @@ runs.
|
|
(Optional, string)
|
|
(Optional, string)
|
|
Reserved for future use.
|
|
Reserved for future use.
|
|
|
|
|
|
|
|
+[[eql-search-api-request-query-param]]
|
|
`query`::
|
|
`query`::
|
|
(Required, string)
|
|
(Required, string)
|
|
<<eql-syntax,EQL>> query you wish to run.
|
|
<<eql-syntax,EQL>> query you wish to run.
|