stack kb security-osquery-api osquery-find-live-queries cli command
Auth required
Idempotent
Scope: global
elastic stack kb security-osquery-api osquery-find-live-queries [options]
Get live queries
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--kuerystring- A KQL search string to filter live queries.
--pagenumber- The page number to return.
--page-sizenumber- The number of results to return per page.
--sortstring- The field to sort results by.
--sort-orderstring- The sort order.
--input-filestring- path to a JSON file to use as command input
--[no-]dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--[no-]json-
output as JSON