# Fleet API vs Fleet UI

**URL:** <https://discuss.elastic.co/t/fleet-api-vs-fleet-ui/283918>\
**Category:** Elasticsearch\
**Tags:** fleet\
**Created:** [September 10, 2021, 8:56pm UTC](https://discuss.elastic.co/t/fleet-api-vs-fleet-ui/283918 "2021-09-10T20:56:54Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![weberr13](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weberr13/32/94437_2.png) [@weberr13](https://discuss.elastic.co/u/weberr13)\
**Post date:** [September 10, 2021, 8:56pm UTC](https://discuss.elastic.co/t/fleet-api-vs-fleet-ui/283918/1 "2021-09-10T20:56:55Z")

</div>

I have been using the fleet openapi spec ([Swagger UI](https://petstore.swagger.io/?url=https://raw.githubusercontent.com/elastic/kibana/7.x/x-pack/plugins/fleet/common/openapi/bundled.json#/default/agent-policy-list)) to programmatically control our agent polices. I have seen 2 issues (I found a work around for one, at a loss for the second).

1. creating an Endpoint policy ignores the "antivirus\_registration" and "popup.\*.message" values on POST requests but _it does work on subsequent PUT_. which is annoying but workable
2. the "agent" setting block for a policy doesn't seem to appear anywhere. I would like to create policies with

```auto
agent:
  monitoring:
    enabled: true
    use_output: default
    namespace: XXX
    logs: true
    metrics: true

```

via the API but I can't find a way to do so. If I try to include these keys in policy creation I get "definition for this key is missing" errors (I tried "agent" and "monitoring")

---

<div class="post-metadata">

**Author:** ![Julia\_Bardi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/julia_bardi/32/79463_2.png) [@Julia\_Bardi](https://discuss.elastic.co/u/Julia_Bardi)\
**Post date:** [September 13, 2021, 1:49pm UTC](https://discuss.elastic.co/t/fleet-api-vs-fleet-ui/283918/2 "2021-09-13T13:49:35Z")

</div>

Hi Robert, could you give a few example curl commands to see the query that you tried to run when encountering these issues?

---

<div class="post-metadata">

**Author:** ![weberr13](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weberr13/32/94437_2.png) [@weberr13](https://discuss.elastic.co/u/weberr13)\
**Post date:** [September 13, 2021, 3:24pm UTC](https://discuss.elastic.co/t/fleet-api-vs-fleet-ui/283918/3 "2021-09-13T15:24:20Z")

</div>

When I did a POST to /api/fleet/package\_policies referencing a valid policy

with (partially redacted with XXX)

```auto
{
		"name": "Endpoint",
		"description": "",
		"namespace": "XXXX",
		"policy_id": "XXXX",
		"enabled": true,
		"output_id": "",
		"inputs": [
			{
			"streams": [],
			"type": "endpoint",
			"config": {
				"artifact_manifest": {
				"value": {
					"schema_version": "v1",
					"manifest_version": "1.0.43",
					"artifacts": {
					"endpoint-trustlist-windows-v1": {
						"relative_url": "/api/fleet/artifacts/endpoint-trustlist-windows-v1/XXX",
						"compression_algorithm": "zlib",
						"decoded_size": 311,
						"decoded_sha256": "XXX",
						"encryption_algorithm": "none",
						"encoded_sha256": "XXX",
						"encoded_size": 153
					},
					"endpoint-eventfilterlist-windows-v1": {
						"relative_url": "/api/fleet/artifacts/endpoint-eventfilterlist-windows-v1/XXX",
						"compression_algorithm": "zlib",
						"decoded_size": 4205,
						"decoded_sha256": "XXX",
						"encryption_algorithm": "none",
						"encoded_sha256": "XXX",
						"encoded_size": 495
					},
					"endpoint-exceptionlist-linux-v1": {
						"relative_url": "/api/fleet/artifacts/endpoint-exceptionlist-linux-v1/XXX",
						"compression_algorithm": "zlib",
						"decoded_size": 14,
						"decoded_sha256": "XXX",
						"encryption_algorithm": "none",
						"encoded_sha256": "XXX",
						"encoded_size": 22
					},
					"endpoint-trustlist-macos-v1": {
						"relative_url": "/api/fleet/artifacts/endpoint-trustlist-macos-v1/XXX",
						"compression_algorithm": "zlib",
						"decoded_size": 14,
						"decoded_sha256": "XXX",
						"encryption_algorithm": "none",
						"encoded_sha256": "XXX",
						"encoded_size": 22
					},
					"endpoint-exceptionlist-macos-v1": {
						"relative_url": "/api/fleet/artifacts/endpoint-exceptionlist-macos-v1/XXX",
						"compression_algorithm": "zlib",
						"decoded_size": 14,
						"decoded_sha256": "XXX",
						"encryption_algorithm": "none",
						"encoded_sha256": "XXX",
						"encoded_size": 22
					},
					"endpoint-trustlist-linux-v1": {
						"relative_url": "/api/fleet/artifacts/endpoint-trustlist-linux-v1/XXX",
						"compression_algorithm": "zlib",
						"decoded_size": 14,
						"decoded_sha256": "XXXX",
						"encryption_algorithm": "none",
						"encoded_sha256": "XXX",
						"encoded_size": 22
					},
					"endpoint-eventfilterlist-linux-v1": {
						"relative_url": "/api/fleet/artifacts/endpoint-eventfilterlist-linux-v1/XXX",
						"compression_algorithm": "zlib",
						"decoded_size": 14,
						"decoded_sha256": "XXX",
						"encryption_algorithm": "none",
						"encoded_sha256": "XXX",
						"encoded_size": 22
					},
					"endpoint-exceptionlist-windows-v1": {
						"relative_url": "/api/fleet/artifacts/endpoint-exceptionlist-windows-v1/XXX",
						"compression_algorithm": "zlib",
						"decoded_size": 14,
						"decoded_sha256": "XXX",
						"encryption_algorithm": "none",
						"encoded_sha256": "XXX",
						"encoded_size": 22
					},
					"endpoint-eventfilterlist-macos-v1": {
						"relative_url": "/api/fleet/artifacts/endpoint-eventfilterlist-macos-v1/XXX",
						"compression_algorithm": "zlib",
						"decoded_size": 14,
						"decoded_sha256": "XXX",
						"encryption_algorithm": "none",
						"encoded_sha256": "XXX",
						"encoded_size": 22
					}
					}
				}
				},
				"policy": {
				"value": {
					"linux": {
					"popup": {
						"malware": {
							"message": "Todyl {action} {filename}",
							"enabled": true
						}
					},
					"malware": {
						"mode": "detect"
					},
					"logging": {
						"file": "info"
					},
					"events": {
						"process": true,
						"file": true,
						"network": true
					}
					},
					"windows": {
					"popup": {
						"malware": {
							"message": "Todyl {action} {filename}",
							"enabled": true
						},
						"ransomware": {
							"message": "Todyl {action} {filename}",
							"enabled": true
						}
					},
					"malware": {
						"mode": "prevent"
					},
					"logging": {
						"file": "info"
					},
					"antivirus_registration": {
						"enabled": true
					},
					"events": {
						"registry": true,
						"process": true,
						"security": true,
						"file": true,
						"dns": true,
						"dll_and_driver_load": true,
						"network": true
					},
					"ransomware": {
						"mode": "prevent",
						"supported": true
					}
					},
					"mac": {
					"popup": {
						"malware": {
						"message": "Todyl {action} {filename}",
						"enabled": true
						}
					},
					"malware": {
						"mode": "prevent"
					},
					"logging": {
						"file": "info"
					},
					"events": {
						"process": true,
						"file": true,
						"network": true
					}
					}
				}
				}
			},
			"enabled": true
			}
		],
		"package": {
			"name": "endpoint",
			"title": "Endpoint Security",
			"version": "1.0.0"
		}
	}

```

the settings

```auto
					"antivirus_registration": {
						"enabled": true
					},
...
					"popup": {
						"malware": {
						"message": "Todyl {action} {filename}",
...

```

didn't stick. When I Re-Ran the exact same json through a PUT to /api/fleet/package\_policies/{{item-ID}} using the item id from the previous response the 2 settings were set.

As for the second half of my question (and the most important part) there doesn't seem to be ANY API to change the agent monitoring settings.

---

<div class="post-metadata">

**Author:** ![Julia\_Bardi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/julia_bardi/32/79463_2.png) [@Julia\_Bardi](https://discuss.elastic.co/u/Julia_Bardi)\
**Post date:** [September 14, 2021, 9:42am UTC](https://discuss.elastic.co/t/fleet-api-vs-fleet-ui/283918/4 "2021-09-14T09:42:21Z")

</div>

okay, I can reproduce 1), raised a bug for Security Solution team here: [https://github.com/elastic/kibana/issues/112075](https://github.com/elastic/kibana/issues/112075)

For 2) you can add monitoring to agent policy like this, the openapi spec should be updated.

```auto
PUT /api/fleet/agent_policies/id
{
   "name": "monitoring agent policy",
   "description": "",
   "namespace": "default",
   "monitoring_enabled": [
      "logs",
      "metrics"
   ]
}

```

---

<div class="post-metadata">

**Author:** ![weberr13](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weberr13/32/94437_2.png) [@weberr13](https://discuss.elastic.co/u/weberr13)\
**Post date:** [September 14, 2021, 3:43pm UTC](https://discuss.elastic.co/t/fleet-api-vs-fleet-ui/283918/5 "2021-09-14T15:43:36Z")

</div>

I tried this and got a 404:

```auto
> curl -s --user 'xxx@todyl.com:xxx' PUT -H 'kbn-xsrf: reporting' -H 'Content-Type: application/json' https://xxx.kb.xxx.aws.found.io:9243/api/fleet/agent_policies/c69e0b50-1276-11ec-bfb3-957669c9ab4e -d @foo.json
{"statusCode":404,"error":"Not Found","message":"Not Found"}

```

with

```auto
{
   "name": "monitoring agent policy",
   "description": "",
   "namespace": "default",
   "monitoring_enabled": [
      "logs",
      "metrics"
   ]
}

```

I also tried with the "name" value matching the policy name to be sure. Neither worked.

and a policy with

```auto
id: c69e0b50-1276-11ec-bfb3-957669c9ab4e
revision: 7
outputs:
  default:
    type: elasticsearch
    hosts:
...
agent:
  monitoring:
    enabled: false
    logs: false
    metrics: false
...

```

and I confirmed I could do a "GET" on that same url and got the policy json back as expected. We are running v7.14.0. Do we need to upgrade?

---

<div class="post-metadata">

**Author:** ![Julia\_Bardi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/julia_bardi/32/79463_2.png) [@Julia\_Bardi](https://discuss.elastic.co/u/Julia_Bardi)\
**Post date:** [September 15, 2021, 6:49am UTC](https://discuss.elastic.co/t/fleet-api-vs-fleet-ui/283918/6 "2021-09-15T06:49:12Z")

</div>

I think it should be there in 7.14 as well.

Can you try changing your command from `PUT` to `-XPUT`?

When you open the UI, do you see Agent monitoring checkboxes when editing an agent policy? It uses the same API to update.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/8/98800b3c2ed4c2c6e2fc82afcd59e17d87090989.png)

---

<div class="post-metadata">

**Author:** ![weberr13](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weberr13/32/94437_2.png) [@weberr13](https://discuss.elastic.co/u/weberr13)\
**Post date:** [September 15, 2021, 3:15pm UTC](https://discuss.elastic.co/t/fleet-api-vs-fleet-ui/283918/7 "2021-09-15T15:15:35Z")

</div>

yes, that was indeed it. Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 13, 2021, 3:16pm UTC](https://discuss.elastic.co/t/fleet-api-vs-fleet-ui/283918/8 "2021-10-13T15:16:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
