stack kb security-osquery-api osquery-create-packs cli command
Auth required
elastic stack kb security-osquery-api osquery-create-packs [options]
Create a pack
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--descriptionstring- The pack description.
--[no-]enabled- Enables the pack.
--intervalnumber- Pack-level interval, in seconds. Used when
schedule_typeisinterval. Mutually exclusive withrrule_schedule. --namestring- The pack name.
--policy-idsstring- A list of agents policy IDs.
--queriesstring- An object of queries.
--rrule-schedulestring- RRULE schedule configuration consumed by osquerybeat. Loose date
--schedule-typestring- Discriminator for the pack's schedule mode.
intervaluses native - An object with shard configuration for policies included in the pack. For each policy, set the shard configuration to a percentage (1–100) of target hosts.
--input-filestring- path to a JSON file to use as command input
--[no-]dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--[no-]json-
output as JSON