stack kb security-exceptions-api update-exception-list-item cli command
Auth required
Idempotent
Scope: global
elastic stack kb security-exceptions-api update-exception-list-item \
--description <description> \
--name <name> \
--type <type> \
[options]
Update an exception list item
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--descriptionstringrequired--namestringrequired--typeenumrequired-
Values: simple
--versionstring- The version ID, normally returned by the API when the item is retrieved. Use it to ensure updates are made against the latest version.
--commentsstring[]-
Repeatable: pass
--commentsmultiple times to supply more than one value --expire-timestring--idstring- Either
idoritem_idmust be specified --item-idstring- Either
idoritem_idmust be specified --metastring--namespace-typeenum-
Values: agnostic, single
--entriesstring[]-
Validation rules:
- Hash entries: up to 3 (one for each hash type: md5, sha1, sha256)
- Path entry: only 1 allowed
Repeatable: pass
--entriesmultiple times to supply more than one value --list-idenum-
Values: endpoint_blocklists
--os-typesstring[]-
macOS-only
Repeatable: pass
--os-typesmultiple times to supply more than one value -
Repeatable: pass
--tagsmultiple times to supply more than one value --input-filestring- path to a JSON file to use as command input
--dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--json-
output as JSON