stack kb security-endpoint-management-api cancel-action cli command
Auth required
elastic stack kb security-endpoint-management-api cancel-action \
--endpoint-ids <endpoint-ids> \
--parameters <parameters> \
[options]
Cancel a response action
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--endpoint-idsstring[]required-
Repeatable: pass
--endpoint-idsmultiple times to supply more than one value --parametersstringrequired--agent-typeenum-
Values: endpoint, sentinel_one, crowdstrike, microsoft_defender_endpoint
--alert-idsstring[]-
If this action is associated with any alerts, they can be specified here. The action will be logged in any cases associated with the specified alerts. Max of 50.
Repeatable: pass
--alert-idsmultiple times to supply more than one value --case-idsstring[]-
The IDs of cases where the action taken will be logged. Max of 50.
Repeatable: pass
--case-idsmultiple times to supply more than one value --commentstring--input-filestring- path to a JSON file to use as command input
--dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--json-
output as JSON