stack kb security-entity-analytics-api create-watchlist cli command
Auth required
elastic stack kb security-entity-analytics-api create-watchlist \
--name <name> \
--risk-modifier <risk-modifier> \
[options]
Create a new watchlist
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--namestringrequired- Unique name for the watchlist
--risk-modifiernumberrequired- Risk score modifier associated with the watchlist
--descriptionstring- Description of the watchlist
--entity-sourcesstring[]-
Optional entity sources to create and link to the watchlist
Repeatable: pass
--entity-sourcesmultiple times to supply more than one value --managed- Indicates if the watchlist is managed by the system
--input-filestring- path to a JSON file to use as command input
--dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--json-
output as JSON