stack kb security-osquery-api osquery-create-live-query cli command
Auth required
elastic stack kb security-osquery-api osquery-create-live-query [options]
Create a live query
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--[no-]agent-all- When
true, the query runs on all agents. --agent-idsstring[]- A list of agent IDs to run the query on.
--agent-platformsstring[]- A list of agent platforms to run the query on.
--agent-policy-idsstring[]- A list of agent policy IDs to run the query on.
--alert-idsstring[]- A list of alert IDs associated with the live query.
--case-idsstring[]- A list of case IDs associated with the live query.
--ecs-mappingstring- Map osquery results columns or static values to Elastic Common Schema (ECS) fields
--event-idsstring[]- A list of event IDs associated with the live query.
--metadatastring- Custom metadata object associated with the live query.
--pack-idstring- The ID of the pack you want to run, retrieve, update, or delete.
--queriesstring[]- An array of queries to run.
--querystring- The SQL query you want to run.
--saved-query-idstring- The ID of a saved query.
--input-filestring- path to a JSON file to use as command input
--[no-]dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--[no-]json-
output as JSON