stack kb security-endpoint-management-api endpoint-isolate-action cli command
Auth required
elastic stack kb security-endpoint-management-api endpoint-isolate-action \
--endpoint-ids <endpoint-ids> \
[options]
Isolate an endpoint
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--endpoint-idsstring[]required-
Repeatable: pass
--endpoint-idsmultiple times to supply more than one value --agent-typeenum-
Values: endpoint, sentinel_one, crowdstrike, microsoft_defender_endpoint
--alert-idsstring[]-
If this action is associated with any alerts, they can be specified here. The action will be logged in any cases associated with the specified alerts. Max of 50.
Repeatable: pass
--alert-idsmultiple times to supply more than one value --case-idsstring[]-
The IDs of cases where the action taken will be logged. Max of 50.
Repeatable: pass
--case-idsmultiple times to supply more than one value --commentstring--parametersstring--input-filestring- path to a JSON file to use as command input
--dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--json-
output as JSON