stack kb security-exceptions-api create-exception-list-item cli command
Auth required
elastic stack kb security-exceptions-api create-exception-list-item \
--description <description> \
--name <name> \
--type <type> \
--list-id <list-id> \
[options]
Create an exception list item
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--descriptionstringrequired--namestringrequired--typeenumrequired-
Values: simple
--list-idenumrequired-
Values: endpoint_blocklists
--commentsstring[]-
Repeatable: pass
--commentsmultiple times to supply more than one value --expire-timestring--item-idstring--metastring--namespace-typeenum-
Values: agnostic, single
--entriesstring[]-
Validation rules:
- Hash entries: up to 3 (one for each hash type: md5, sha1, sha256)
- Path entry: only 1 allowed
Repeatable: pass
--entriesmultiple times to supply more than one value --os-typesstring[]-
macOS-only
Repeatable: pass
--os-typesmultiple times to supply more than one value -
Repeatable: pass
--tagsmultiple times to supply more than one value --input-filestring- path to a JSON file to use as command input
--dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--json-
output as JSON