stack kb security-osquery-api osquery-create-live-query cli command

Auth required
elastic stack kb security-osquery-api osquery-create-live-query [options]
		

Create a live query

Behaviour flags:

--dry-run — validate all inputs and exit without performing any action

--agent-all
When true, the query runs on all agents.
--agent-ids string[]
A list of agent IDs to run the query on.
--agent-platforms string[]
A list of agent platforms to run the query on.
--agent-policy-ids string[]
A list of agent policy IDs to run the query on.
--alert-ids string[]
A list of alert IDs associated with the live query.
--case-ids string[]
A list of case IDs associated with the live query.
--ecs-mapping string
--event-ids string[]
A list of event IDs associated with the live query.
--metadata string
Custom metadata object associated with the live query.
--pack-id string
--queries string[]
--query string
--saved-query-id string
--input-file string
path to a JSON file to use as command input
--dry-run
validate all inputs and exit without performing any action (preview changes without applying them)
--json

output as JSON