stack kb security-endpoint-management-api endpoint-get-actions-list cli command
elastic stack kb security-endpoint-management-api endpoint-get-actions-list \
[options]
Get response actions
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--pagenumber- The page number to return.
--page-sizenumber- The number of response actions to return per page.
--commandsstring[]-
A list of response action command names to filter by.
Repeatable: pass
--commandsmultiple times to supply more than one value --agent-idsstring-
A list of Elastic Agent IDs to filter the response actions by.
Repeatable: pass
--agent-idsmultiple times to supply more than one value --user-idsstring-
A list of user IDs that submitted the response actions.
Repeatable: pass
--user-idsmultiple times to supply more than one value --start-datestring- A start date in ISO 8601 format or Date Math format (for example,
now-24h). --end-datestring- An end date in ISO 8601 format or Date Math format (for example,
now). --agent-typesenum-
The agent type to filter response actions by. Defaults to
endpoint.Values: endpoint, sentinel_one, crowdstrike, microsoft_defender_endpoint
--with-outputsstring-
A list of response action IDs whose outputs should be included in the response.
Repeatable: pass
--with-outputsmultiple times to supply more than one value --typesstring[]-
A list of response action types to filter by (
automated,manual).Repeatable: pass
--typesmultiple times to supply more than one value --input-filestring- path to a JSON file to use as command input
--dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--json-
output as JSON