stack kb security-osquery-api osquery-create-live-query cli command
elastic stack kb security-osquery-api osquery-create-live-query [options]
Create a live query
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--agent-all- When
true, the query runs on all agents. --agent-idsstring[]-
A list of agent IDs to run the query on.
Repeatable: pass
--agent-idsmultiple times to supply more than one value --agent-platformsstring[]-
A list of agent platforms to run the query on.
Repeatable: pass
--agent-platformsmultiple times to supply more than one value --agent-policy-idsstring[]-
A list of agent policy IDs to run the query on.
Repeatable: pass
--agent-policy-idsmultiple times to supply more than one value --alert-idsstring[]-
A list of alert IDs associated with the live query.
Repeatable: pass
--alert-idsmultiple times to supply more than one value --case-idsstring[]-
A list of case IDs associated with the live query.
Repeatable: pass
--case-idsmultiple times to supply more than one value --ecs-mappingstring--event-idsstring[]-
A list of event IDs associated with the live query.
Repeatable: pass
--event-idsmultiple times to supply more than one value --metadatastring- Custom metadata object associated with the live query.
--pack-idstring--queriesstring[]-
Repeatable: pass
--queriesmultiple times to supply more than one value --querystring--saved-query-idstring--input-filestring- path to a JSON file to use as command input
--dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--json-
output as JSON