stack kb security-endpoint-management-api endpoint-scan-action cli command
Auth required
elastic stack kb security-endpoint-management-api endpoint-scan-action \
--endpoint-ids <endpoint-ids> \
--parameters <parameters> \
[options]
Scan a file or directory
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--endpoint-idsstringrequired- List of endpoint IDs (cannot contain empty strings). Max of 250.
--parametersstringrequired--agent-typestring- List of agent types to retrieve. Defaults to
endpoint. --alert-idsstring- If this action is associated with any alerts, they can be specified here. The action will be logged in any cases associated with the specified alerts. Max of 50.
--case-idsstring- The IDs of cases where the action taken will be logged. Max of 50.
--commentstring- Optional comment
--input-filestring- path to a JSON file to use as command input
--[no-]dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--[no-]json-
output as JSON