stack es security saml-invalidate cli command
Auth required
elastic stack es security saml-invalidate \
--query-string <query-string> \
[options]
Invalidate SAML.
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--query-stringstringrequired- The query part of the URL that the user was redirected to by the SAML IdP to initiate the Single Logout.
This query should include a single parameter named
SAMLRequestthat contains a SAML logout request that is deflated and Base64 encoded. If the SAML IdP has signed the logout request, the URL should include two extra parameters namedSigAlgandSignaturethat contain the algorithm used for the signature and the signature value itself. In order for Elasticsearch to be able to verify the IdP's signature, the value of thequery_stringfield must be an exact match to the string provided by the browser. The client application must not attempt to parse or process the string in any way. --acsstring- The Assertion Consumer Service URL that matches the one of the SAML realm in Elasticsearch that should be used. You must specify either this parameter or the
realmparameter. --realmstring- The name of the SAML realm in Elasticsearch the configuration. You must specify either this parameter or the
acsparameter. --error-trace- When set to
trueElasticsearch will include the full stack trace of errors when they occur. --filter-pathstring-
Comma-separated list of filters in dot notation which reduce the response returned by Elasticsearch.
Repeatable: pass
--filter-pathmultiple times to supply more than one value --human- When set to
truewill return statistics in a format suitable for humans. For example"exists_time": "1h"for humans and"exists_time_in_millis": 3600000for computers. When disabled the human readable values will be omitted. This makes sense for responses being consumed only by machines. --pretty- If set to
truethe returned JSON will be "pretty-formatted". Only use this option for debugging only. --input-filestring- path to a JSON file to use as command input
--dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--json-
output as JSON