Updates the saved search data in Intel Exchange.
Path Parameters
| Name | Type | Required | Description |
|---|---|---|---|
| id | string | optional | Pass the unique ID of a saved search to be update. You can retrieve the ID using the List Saved Searches API. Example, 1a7d5c8a-848a-4a67-af82-e68f3d823c65. |
Body Parameters
| Name | Type | Required | Description |
|---|---|---|---|
| type | string | required | Pass the type of the saved search. |
| name | string | required | Pass the name of the saved search. |
| description | string | optional | Pass the description of the saved search. |
| query | string | required | Pass the updated search query. |
| shared_type | string | optional | Pass the privacy parameter of the saved search. |
| meta_data | string | optional | Pass the metadata of the saved search that helps in the transformation to the CQL query or threat data filters. |
Run it
Use the Request parameters panel to enter path IDs, query values, JSON body, and credentials. Then run any snippet below — all languages use the same values. Base URL: https://cs-testv2.cyware.com/ctixapi (change in API Settings).
Playground
Request parameters
Edit values here before running any snippet below (cURL, JavaScript, or Python). Code blocks are reference only — your inputs above are what gets sent.
Open API (HMAC signature) · Get credentials from Cyware Admin → Open API → Generate Credentials.
Signature and Expires are generated when you run a request. Access ID and Secret Key stay in memory for this tab only.
Credentials from Authentication auto-fill here for this product. If fields are empty after connecting, refresh this page or open the product docs again.
curl --request PUT \
--url "https://cs-testv2.cyware.com/ctixapi/ingestion/saved-searches/{id}/?AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E" \
--data '{
"type": "basic",
"name": "Indicator Search",
"description": "Indicator search",
"query": "type=\"indicator\" and sub_type=\"file\" and created>\"2021-07-28\"",
"shared_type": "global",
"meta_data": "{\"object_type\":[\"malware\"],\"query\":[{\"length\":26,\"dataKey\":{\"id\":\"type\",\"type\":\"select\",\"addAll\":true,\"reset\":true,\"multiple\":true,\"value\":\"id\",\"label\":\"Object Type\",\"values\":[{\"id\":\"indicator\",\"name\":\"Indicator\"},{\"id\":\"malware\",\"name\":\"Malware\"},{\"id\":\"threat-actor\",\"name\":\"Threat Actor\"},{\"id\":\"vulnerability\",\"name\":\"Vulnerability\"},{\"id\":\"attack-pattern\",\"name\":\"Attack Pattern\"},{\"id\":\"campaign\",\"name\":\"Campaign\"},{\"id\":\"course-of-action\",\"name\":\"Course of Action\"},{\"id\":\"identity\",\"name\":\"Identity\"},{\"id\":\"infrastructure\",\"name\":\"Infrastructure\"},{\"id\":\"intrusion-set\",\"name\":\"Intrusion Set\"},{\"id\":\"location\",\"name\":\"Location\"},{\"id\":\"malware-analysis\",\"name\":\"Malware Analysis\"},{\"id\":\"observed-data\",\"name\":\"Observed Data\"},{\"id\":\"opinion\",\"name\":\"Opinion\"},{\"id\":\"tool\",\"name\":\"Tool\"},{\"id\":\"report\",\"name\":\"Report\"},{\"id\":\"custom-object\",\"name\":\"Custom Object\"},{\"id\":\"observable\",\"name\":\"Observable\"},{\"id\":\"incident\",\"name\":\"Incident\"}]},\"key\":\"'Object Type'\",\"keyType\":\"select\",\"dataOperator\":{\"id\":\"=\",\"label\":\"=\"},\"operator\":\"=\",\"dataValue\":{\"id\":\"malware\",\"name\":\"Malware\"},\"value\":\"\\\"Malware\\\"\"}]}"
}'View-only example — running live API calls requires a role with snippet testing access.
const url = "https://cs-testv2.cyware.com/ctixapi/ingestion/saved-searches/{id}/?AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E";
const response = await fetch(url, {
method: "PUT",
headers: {},
body: JSON.stringify({
"type": "basic",
"name": "Indicator Search",
"description": "Indicator search",
"query": "type=\"indicator\" and sub_type=\"file\" and created>\"2021-07-28\"",
"shared_type": "global",
"meta_data": "{\"object_type\":[\"malware\"],\"query\":[{\"length\":26,\"dataKey\":{\"id\":\"type\",\"type\":\"select\",\"addAll\":true,\"reset\":true,\"multiple\":true,\"value\":\"id\",\"label\":\"Object Type\",\"values\":[{\"id\":\"indicator\",\"name\":\"Indicator\"},{\"id\":\"malware\",\"name\":\"Malware\"},{\"id\":\"threat-actor\",\"name\":\"Threat Actor\"},{\"id\":\"vulnerability\",\"name\":\"Vulnerability\"},{\"id\":\"attack-pattern\",\"name\":\"Attack Pattern\"},{\"id\":\"campaign\",\"name\":\"Campaign\"},{\"id\":\"course-of-action\",\"name\":\"Course of Action\"},{\"id\":\"identity\",\"name\":\"Identity\"},{\"id\":\"infrastructure\",\"name\":\"Infrastructure\"},{\"id\":\"intrusion-set\",\"name\":\"Intrusion Set\"},{\"id\":\"location\",\"name\":\"Location\"},{\"id\":\"malware-analysis\",\"name\":\"Malware Analysis\"},{\"id\":\"observed-data\",\"name\":\"Observed Data\"},{\"id\":\"opinion\",\"name\":\"Opinion\"},{\"id\":\"tool\",\"name\":\"Tool\"},{\"id\":\"report\",\"name\":\"Report\"},{\"id\":\"custom-object\",\"name\":\"Custom Object\"},{\"id\":\"observable\",\"name\":\"Observable\"},{\"id\":\"incident\",\"name\":\"Incident\"}]},\"key\":\"'Object Type'\",\"keyType\":\"select\",\"dataOperator\":{\"id\":\"=\",\"label\":\"=\"},\"operator\":\"=\",\"dataValue\":{\"id\":\"malware\",\"name\":\"Malware\"},\"value\":\"\\\"Malware\\\"\"}]}"
}),
});
const text = await response.text();
let data;
try { data = JSON.parse(text); } catch { data = text; }
console.log(response.status, data);View-only example — running live API calls requires a role with snippet testing access.
import requests
url = "https://cs-testv2.cyware.com/ctixapi/ingestion/saved-searches/{id}/"
params = {
"AccessID": "<your access id>",
"Signature": "<your signature>",
"Expires": "<your expires>"
}
headers = {}
payload = {
"type": "basic",
"name": "Indicator Search",
"description": "Indicator search",
"query": "type=\"indicator\" and sub_type=\"file\" and created>\"2021-07-28\"",
"shared_type": "global",
"meta_data": "{\"object_type\":[\"malware\"],\"query\":[{\"length\":26,\"dataKey\":{\"id\":\"type\",\"type\":\"select\",\"addAll\":true,\"reset\":true,\"multiple\":true,\"value\":\"id\",\"label\":\"Object Type\",\"values\":[{\"id\":\"indicator\",\"name\":\"Indicator\"},{\"id\":\"malware\",\"name\":\"Malware\"},{\"id\":\"threat-actor\",\"name\":\"Threat Actor\"},{\"id\":\"vulnerability\",\"name\":\"Vulnerability\"},{\"id\":\"attack-pattern\",\"name\":\"Attack Pattern\"},{\"id\":\"campaign\",\"name\":\"Campaign\"},{\"id\":\"course-of-action\",\"name\":\"Course of Action\"},{\"id\":\"identity\",\"name\":\"Identity\"},{\"id\":\"infrastructure\",\"name\":\"Infrastructure\"},{\"id\":\"intrusion-set\",\"name\":\"Intrusion Set\"},{\"id\":\"location\",\"name\":\"Location\"},{\"id\":\"malware-analysis\",\"name\":\"Malware Analysis\"},{\"id\":\"observed-data\",\"name\":\"Observed Data\"},{\"id\":\"opinion\",\"name\":\"Opinion\"},{\"id\":\"tool\",\"name\":\"Tool\"},{\"id\":\"report\",\"name\":\"Report\"},{\"id\":\"custom-object\",\"name\":\"Custom Object\"},{\"id\":\"observable\",\"name\":\"Observable\"},{\"id\":\"incident\",\"name\":\"Incident\"}]},\"key\":\"'Object Type'\",\"keyType\":\"select\",\"dataOperator\":{\"id\":\"=\",\"label\":\"=\"},\"operator\":\"=\",\"dataValue\":{\"id\":\"malware\",\"name\":\"Malware\"},\"value\":\"\\\"Malware\\\"\"}]}"
}
response = requests.request("PUT", url, params=params, headers=headers, json=payload)
print(response.status_code)
print(response.text)View-only example — running live API calls requires a role with snippet testing access.
{
"type": "basic",
"name": "Indicator Search",
"description": "Indicator search",
"query": "type=\"indicator\" and sub_type=\"file\" and created>\"2021-07-28\"",
"shared_type": "global",
"meta_data": "{\"object_type\":[\"malware\"],\"query\":[{\"length\":26,\"dataKey\":{\"id\":\"type\",\"type\":\"select\",\"addAll\":true,\"reset\":true,\"multiple\":true,\"value\":\"id\",\"label\":\"Object Type\",\"values\":[{\"id\":\"indicator\",\"name\":\"Indicator\"},{\"id\":\"malware\",\"name\":\"Malware\"},{\"id\":\"threat-actor\",\"name\":\"Threat Actor\"},{\"id\":\"vulnerability\",\"name\":\"Vulnerability\"},{\"id\":\"attack-pattern\",\"name\":\"Attack Pattern\"},{\"id\":\"campaign\",\"name\":\"Campaign\"},{\"id\":\"course-of-action\",\"name\":\"Course of Action\"},{\"id\":\"identity\",\"name\":\"Identity\"},{\"id\":\"infrastructure\",\"name\":\"Infrastructure\"},{\"id\":\"intrusion-set\",\"name\":\"Intrusion Set\"},{\"id\":\"location\",\"name\":\"Location\"},{\"id\":\"malware-analysis\",\"name\":\"Malware Analysis\"},{\"id\":\"observed-data\",\"name\":\"Observed Data\"},{\"id\":\"opinion\",\"name\":\"Opinion\"},{\"id\":\"tool\",\"name\":\"Tool\"},{\"id\":\"report\",\"name\":\"Report\"},{\"id\":\"custom-object\",\"name\":\"Custom Object\"},{\"id\":\"observable\",\"name\":\"Observable\"},{\"id\":\"incident\",\"name\":\"Incident\"}]},\"key\":\"'Object Type'\",\"keyType\":\"select\",\"dataOperator\":{\"id\":\"=\",\"label\":\"=\"},\"operator\":\"=\",\"dataValue\":{\"id\":\"malware\",\"name\":\"Malware\"},\"value\":\"\\\"Malware\\\"\"}]}"
}View-only example — running live API calls requires a role with snippet testing access.
{
"created_by": {},
"description": "Indicator search",
"editable": true,
"id": "1a7d5c8a-848a-4a67-af82-e68f3d823c65",
"is_threat_data_search": true,
"meta_data": "{\"object_type\":[\"malware\"],\"query\":[{\"length\":26,\"dataKey\":{\"id\":\"type\",\"type\":\"select\",\"addAll\":true,\"reset\":true,\"multiple\":true,\"value\":\"id\",\"label\":\"Object Type\",\"values\":[{\"id\":\"indicator\",\"name\":\"Indicator\"},{\"id\":\"malware\",\"name\":\"Malware\"},{\"id\":\"threat-actor\",\"name\":\"Threat Actor\"},{\"id\":\"vulnerability\",\"name\":\"Vulnerability\"},{\"id\":\"attack-pattern\",\"name\":\"Attack Pattern\"},{\"id\":\"campaign\",\"name\":\"Campaign\"},{\"id\":\"course-of-action\",\"name\":\"Course of Action\"},{\"id\":\"identity\",\"name\":\"Identity\"},{\"id\":\"infrastructure\",\"name\":\"Infrastructure\"},{\"id\":\"intrusion-set\",\"name\":\"Intrusion Set\"},{\"id\":\"location\",\"name\":\"Location\"},{\"id\":\"malware-analysis\",\"name\":\"Malware Analysis\"},{\"id\":\"observed-data\",\"name\":\"Observed Data\"},{\"id\":\"opinion\",\"name\":\"Opinion\"},{\"id\":\"tool\",\"name\":\"Tool\"},{\"id\":\"report\",\"name\":\"Report\"},{\"id\":\"custom-object\",\"name\":\"Custom Object\"},{\"id\":\"observable\",\"name\":\"Observable\"},{\"id\":\"incident\",\"name\":\"Incident\"}]},\"key\":\"'Object Type'\",\"keyType\":\"select\",\"dataOperator\":{\"id\":\"=\",\"label\":\"=\"},\"operator\":\"=\",\"dataValue\":{\"id\":\"malware\",\"name\":\"Malware\"},\"value\":\"\\\"Malware\\\"\"}]}",
"name": "Indicator Search",
"order": 2,
"pinned": false,
"query": "type=\"indicator\" and sub_type=\"file\" and created>\"2021-07-28\"",
"shared_type": "global",
"shared_users": [],
"type": "basic"
}View-only example — running live API calls requires a role with snippet testing access.