stack kb security-exceptions-api update-exception-list cli command
Auth required
Idempotent
Scope: global
elastic stack kb security-exceptions-api update-exception-list \
--description <description> \
--name <name> \
--type <type> \
[options]
Update an exception list
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--descriptionstringrequired--namestringrequired--typeenumrequired-
Values: detection, rule_default, endpoint, endpoint_trusted_apps, endpoint_trusted_devices, endpoint_events, endpoint_host_isolation_exceptions, endpoint_blocklists, endpoint_custom_yara_signatures
--versionstring- The version id, normally returned by the API when the item was retrieved. Use it ensure updates are done against the latest version.
--idstring--list-idstring--metastring--namespace-typeenum-
Values: agnostic, single
--os-typesstring[]-
Repeatable: pass
--os-typesmultiple times to supply more than one value -
Repeatable: pass
--tagsmultiple times to supply more than one value --x-versionnumber--input-filestring- path to a JSON file to use as command input
--dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--json-
output as JSON