stack kb security-osquery-api osquery-get-live-query-results cli command
Auth required
Idempotent
Scope: global
elastic stack kb security-osquery-api osquery-get-live-query-results \
--id <id> \
--action-id <action-id> \
[options]
Get live query results
--idstringrequired- The id parameter
--action-idstringrequired- The actionId parameter
--kuerystring--pagenumber--page-sizenumber--sortstring--sort-orderstring
--input-filestring- path to a JSON file to use as command input
-V--[no-]version- Print the Elastic CLI version
--config-filestring- path to a config file (default: ~/.elasticrc.yml)
--use-contextstring- override the active context from the config file
--command-profilestring- restrict available commands to a deployment profile (serverless, stack, default)
--[no-]json- output as JSON
--output-fieldsstring- comma-separated list of fields to include in output (dot-notation supported)
--output-templatestring- Mustache-like template for custom text output (e.g. "{{id}}: {{name}}")
--[no-]dry-run-
validate all inputs and exit without performing any action (preview changes without applying them)