stack es eql get cli command
Auth required
Idempotent
Scope: global
elastic stack es eql get --id <id> [options]
Get async EQL search results.
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--idstringrequired- Identifier for the search.
--keep-alivestring- Period for which the search and its results are stored on the cluster. Defaults to the keep_alive value set by the search’s EQL search API request.
--wait-for-completion-timeoutstring- Timeout duration to wait for the request to finish. Defaults to no timeout, meaning the request waits for complete search results.
--error-trace- When set to
trueElasticsearch will include the full stack trace of errors when they occur. --filter-pathstring-
Comma-separated list of filters in dot notation which reduce the response returned by Elasticsearch.
Repeatable: pass
--filter-pathmultiple times to supply more than one value --human- When set to
truewill return statistics in a format suitable for humans. For example"exists_time": "1h"for humans and"exists_time_in_millis": 3600000for computers. When disabled the human readable values will be omitted. This makes sense for responses being consumed only by machines. --pretty- If set to
truethe returned JSON will be "pretty-formatted". Only use this option for debugging only. --input-filestring- path to a JSON file to use as command input
--dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--json-
output as JSON