Andrew Mercer
on this page

    Kibana APIs need the kbn-xsrf header on anything that isn't a GET. In a non-default space, prefix the path with /s/<space_id>, for example $KIBANA_URL/s/ops/api/saved_objects/_find.

    in this section
    * export all saved objects
    * find data views with scripted fields