---
title: "Changes to Bulk update Attack discoveries"
method: POST
path: "/api/attack_discovery/_bulk"
---

# Changes to Bulk update Attack discoveries

`POST /api/attack_discovery/_bulk`

> Every recorded change to this endpoint, newest first.
> 176 revisions in range; 20 not diffed.

## Timeline

Changed in 1 of 176 revisions.

- **2026-09-09** `887252c0434a` — 1 info

## Changes

- **2026-09-09** `887252c0434a` — 1 info
  - added the optional property `data/items/alert_workflow_reason` to the response with the `200` status

---

[Operation](https://skmtc.dev/elastic/apis/kibana-apis/docs/api/attack_discovery/_bulk/post.md) · [API](https://skmtc.dev/elastic/apis/kibana-apis.md) · [Page](https://skmtc.dev/elastic/apis/kibana-apis/changes/api/attack_discovery/_bulk/post)
