---
title: "Disable the history snapshot task"
method: PUT
path: "/api/security/entity_store/history_snapshot/disable"
tags: ["Security entity store"]
---

# Disable the history snapshot task

`PUT /api/security/entity_store/history_snapshot/disable`

**Spaces method and path for this operation:**

<div><span class="operation-verb put">put</span>&nbsp;<span class="operation-path">/s/{space_id}/api/security/entity_store/history_snapshot/disable</span></div>

Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information.

Disable the Entity Store history snapshot task for this space so it no longer creates snapshot indices. Existing snapshot indices remain unless you set `clearHistorySnapshots` to `true`. Returns 404 if the Entity Store is not installed in the current space.<br/><br/>[Required authorization] Route required privileges: securitySolution.

## Headers

- `kbn-xsrf` string, required

## Request body

- object
  - `clearHistorySnapshots` boolean — When `true`, deletes existing history snapshot indices for this space in the background after the task is disabled. The response returns immediately and does not wait for deletion to finish. Deletion failures are logged and are not returned to the caller. If the task is already disabled, the request succeeds and does not delete indices. Defaults to `false`.

## Response `200`

Indicates a successful response.

## Other responses

- `404` — Entity store is not installed.

## Changes

> 176 revisions in range; 20 not diffed.

- **2026-09-21** `729f4dac7620` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/elastic/apis/kibana-apis/changes/api/security/entity_store/history_snapshot/disable/put.md)

---

[API](https://skmtc.dev/elastic/apis/kibana-apis.md) · [All operations](https://skmtc.dev/elastic/apis/kibana-apis/llms.txt) · [OpenAPI document](https://skmtc.dev/elastic/apis/kibana-apis/revisions/84f30e7da461?raw)
