# Elastic Stack (ELK Stack) Security Endpoint Management API

**Canonical:** https://apis.io/apis/elk-stack/elk-stack-security-endpoint-management-api-api/  
**Provider:** Elastic Stack (ELK Stack) — https://apis.io/providers/elk-stack/  
**Base URL:** https://{elasticsearch_endpoint}  
**Documentation:** https://www.elastic.co/docs/api/doc/elasticsearch/

Elastic Stack (ELK Stack) Security Endpoint Management API is one of 132 APIs that [Elastic Stack (ELK Stack)](https://apis.io/providers/elk-stack/) publishes on the [APIs.io](https://apis.io/) network, described by a machine-readable OpenAPI specification. Tagged areas include Security Endpoint Management API. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.

Interact with and manage endpoints running the Elastic Defend integration.

## Operations (29)

| Method | Path | Summary |
|---|---|---|
| GET | `/api/endpoint/action` | Get response actions |
| GET | `/api/endpoint/action_status` | Get response actions status |
| GET | `/api/endpoint/action/{action_id}` | Get action details |
| GET | `/api/endpoint/action/{action_id}/file/{file_id}` | Get file information |
| GET | `/api/endpoint/action/{action_id}/file/{file_id}/download` | Download a file |
| POST | `/api/endpoint/action/cancel` | Cancel a response action |
| POST | `/api/endpoint/action/execute` | Run a command |
| POST | `/api/endpoint/action/get_file` | Get a file |
| POST | `/api/endpoint/action/isolate` | Isolate an endpoint |
| POST | `/api/endpoint/action/kill_process` | Terminate a process |
| POST | `/api/endpoint/action/memory_dump` | Generate a memory dump from the host machine |
| POST | `/api/endpoint/action/run_script` | Run a script |
| POST | `/api/endpoint/action/running_procs` | Get running processes |
| POST | `/api/endpoint/action/scan` | Scan a file or directory |
| GET | `/api/endpoint/action/state` | Get actions state |
| POST | `/api/endpoint/action/suspend_process` | Suspend a process |
| POST | `/api/endpoint/action/unisolate` | Release an isolated endpoint |
| POST | `/api/endpoint/action/upload` | Upload a file |
| GET | `/api/endpoint/metadata` | Get a metadata list |
| GET | `/api/endpoint/metadata/{id}` | Get metadata |
| GET | `/api/endpoint/policy_response` | Get a policy response |
| GET | `/api/endpoint/protection_updates_note/{package_policy_id}` | Get a protection updates note |
| POST | `/api/endpoint/protection_updates_note/{package_policy_id}` | Create or update a protection updates note |
| GET | `/api/endpoint/scripts_library` | Get a list of scripts |
| POST | `/api/endpoint/scripts_library` | Create script |
| DELETE | `/api/endpoint/scripts_library/{script_id}` | Delete a script |
| GET | `/api/endpoint/scripts_library/{script_id}` | Get script |
| PATCH | `/api/endpoint/scripts_library/{script_id}` | Update script |
| GET | `/api/endpoint/scripts_library/{script_id}/download` | Download a script file |

## Machine-readable artifacts (8)

- **OpenAPI** — https://raw.githubusercontent.com/api-evangelist/elk-stack/refs/heads/main/openapi/elk-stack-security-endpoint-management-api-api-openapi.yml
- **Documentation** — https://www.elastic.co/docs/reference/elasticsearch
- **APIReference** — https://www.elastic.co/docs/api/doc/elasticsearch/
- **SourceCode** — https://github.com/elastic/elasticsearch-specification
- **Documentation** — https://www.elastic.co/docs/reference/kibana
- **APIReference** — https://www.elastic.co/docs/api/doc/kibana/
- **SourceCode** — https://github.com/elastic/kibana
- **ToolCrosswalk** — https://raw.githubusercontent.com/api-evangelist/elk-stack/refs/heads/main/mcp/elk-stack-tool-crosswalk.yml

## Other Elastic Stack (ELK Stack) APIs (12)

- [Elastic Cloud API](https://apis.io/apis/elk-stack/elastic-cloud-api/)
- [Elastic Stack (ELK Stack) Accounts API](https://apis.io/apis/elk-stack/elk-stack-accounts-api/)
- [Elastic Stack (ELK Stack) Actions API](https://apis.io/apis/elk-stack/elk-stack-actions-api/)
- [Elastic Stack (ELK Stack) agent builder API](https://apis.io/apis/elk-stack/elk-stack-agent-builder-api/)
- [Elastic Stack (ELK Stack) Alerting API](https://apis.io/apis/elk-stack/elk-stack-alerting-api/)
- [Elastic Stack (ELK Stack) Alerting V2 API](https://apis.io/apis/elk-stack/elk-stack-alerting-v2-api/)
- [Elastic Stack (ELK Stack) Analytics API](https://apis.io/apis/elk-stack/elk-stack-analytics-api/)
- [Elastic Stack (ELK Stack) APM agent configuration API](https://apis.io/apis/elk-stack/elk-stack-apm-agent-configuration-api/)
- [Elastic Stack (ELK Stack) APM agent keys API](https://apis.io/apis/elk-stack/elk-stack-apm-agent-keys-api/)
- [Elastic Stack (ELK Stack) APM annotations API](https://apis.io/apis/elk-stack/elk-stack-apm-annotations-api/)
- [Elastic Stack (ELK Stack) APM server schema API](https://apis.io/apis/elk-stack/elk-stack-apm-server-schema-api/)
- [Elastic Stack (ELK Stack) APM sourcemaps API](https://apis.io/apis/elk-stack/elk-stack-apm-sourcemaps-api/)

## Tags

Security Endpoint Management API

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/apis/elk-stack/elk-stack-security-endpoint-management-api-api/). The API's provider profile, Kin Score and agent-readiness rating are at https://apis.io/providers/elk-stack/.
