stack kb cases get-cases-by-alert cli command
Auth required
Idempotent
Scope: global
elastic stack kb cases get-cases-by-alert --alert-id <alert-id> [options]
Get cases for an alert
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--alert-idstringrequired- An identifier for the alert.
--ownerstring-
A filter to limit the response to a specific set of applications. If this parameter is omitted, the response contains information about all the cases that the user has access to read.
Repeatable: pass
--ownermultiple times to supply more than one value --input-filestring- path to a JSON file to use as command input
--dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--json-
output as JSON