stack kb security-osquery-api osquery-create-live-query cli command

Auth required
elastic stack kb security-osquery-api osquery-create-live-query [options]
		

Create a live query

Behaviour flags:

--dry-run — validate all inputs and exit without performing any action

--agent-all
When true, the query runs on all agents.
--agent-ids string[]

A list of agent IDs to run the query on.

Repeatable: pass --agent-ids multiple times to supply more than one value

--agent-platforms string[]

A list of agent platforms to run the query on.

Repeatable: pass --agent-platforms multiple times to supply more than one value

--agent-policy-ids string[]

A list of agent policy IDs to run the query on.

Repeatable: pass --agent-policy-ids multiple times to supply more than one value

--alert-ids string[]

A list of alert IDs associated with the live query.

Repeatable: pass --alert-ids multiple times to supply more than one value

--case-ids string[]

A list of case IDs associated with the live query.

Repeatable: pass --case-ids multiple times to supply more than one value

--ecs-mapping string
--event-ids string[]

A list of event IDs associated with the live query.

Repeatable: pass --event-ids multiple times to supply more than one value

--metadata string
Custom metadata object associated with the live query.
--pack-id string
--queries string[]

Repeatable: pass --queries multiple times to supply more than one value

--query string
--saved-query-id string
--input-file string
path to a JSON file to use as command input
--dry-run
validate all inputs and exit without performing any action (preview changes without applying them)
--json

output as JSON