stack kb security-entity-analytics-api configure-risk-engine-saved-object cli command
Auth required
Idempotent
Scope: global
elastic stack kb security-entity-analytics-api configure-risk-engine-saved-object \
[options]
Configure the Risk Engine Saved Object
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--enable-reset-to-zero--exclude-alert-statusesstring[]-
Repeatable: pass
--exclude-alert-statusesmultiple times to supply more than one value -
Repeatable: pass
--exclude-alert-tagsmultiple times to supply more than one value --filtersstring[]-
Repeatable: pass
--filtersmultiple times to supply more than one value --page-sizenumber- Number of entities to score per page. Higher values reduce total scoring time by reducing the number of alert-index scans, but cannot exceed the ES|QL result limit (10,000 by default).
--rangestring--input-filestring- path to a JSON file to use as command input
--dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--json-
output as JSON