stack kb cases update-case-field-definition-default-space cli command
Auth required
Idempotent
Scope: global
elastic stack kb cases update-case-field-definition-default-space \
--field-definition-id <field-definition-id> \
--definition <definition> \
--owner <owner> \
[options]
Update a field definition
--field-definition-idstringrequired- The identifier for the field definition.
--definitionstringrequired- The field definition as a YAML string describing a single field (type, label, control, metadata).
--ownerstringrequired- The application that owns this field definition.
--dry-run- When true, runs authorization, body, and identity-immutability validation without updating the field definition. Returns
{ "valid": true }on success. --descriptionstring- Optional human-readable description of the field's purpose.
--is-global- When true, this field is rendered in every case for this owner, regardless of the template used. Global fields cannot be demoted (set to false) while they are linked to an active custom field in the Cases configuration.
--namestring- The field name, unique per owner (case-insensitive). Must match the
namekey inside the YAML definition. When omitted, the name is extracted from the definition YAML automatically. Immutable after creation. Unlike POST, the 50-character limit is not enforced on PUT so that definitions with legacy names that exceed the limit remain modifiable. --input-filestring- path to a JSON file to use as command input
--no-validate- skip input validation and send the request as-is
--output-fieldsstring- comma-separated list of fields to include in output (dot-notation supported)
--output-templatestring- Mustache-like template for custom text output (e.g. "{{id}}: {{name}}")
--json-
output as JSON