stack kb security-entity-analytics-api unassign-watchlist-entities cli command
Auth required
elastic stack kb security-entity-analytics-api unassign-watchlist-entities \
--watchlist-id <watchlist-id> \
--euids <euids> \
[options]
Manually unassign entities from a watchlist
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--watchlist-idstringrequired- The ID of the watchlist to remove entities from
--euidsstring[]required-
The EUIDs of the entities to unassign
Repeatable: pass
--euidsmultiple times to supply more than one value --input-filestring- path to a JSON file to use as command input
--dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--json-
output as JSON