Loading

stack kb security-osquery-api osquery-create-packs cli command

Auth required
elastic stack kb security-osquery-api osquery-create-packs [options]
		

Create a pack

Behaviour flags:

--dry-run — validate all inputs and exit without performing any action

--description string
The pack description.
--[no-]enabled
Enables the pack.
--interval number
Pack-level interval, in seconds. Used when schedule_type is interval. Mutually exclusive with rrule_schedule.
--name string
The pack name.
--policy-ids string
A list of agents policy IDs.
--queries string
An object of queries.
--rrule-schedule string
RRULE schedule configuration consumed by osquerybeat. Loose date
--schedule-type string
Discriminator for the pack's schedule mode. interval uses native
--shards string
An object with shard configuration for policies included in the pack. For each policy, set the shard configuration to a percentage (1–100) of target hosts.
--input-file string
path to a JSON file to use as command input
--[no-]dry-run
validate all inputs and exit without performing any action (preview changes without applying them)
--[no-]json

output as JSON