stack kb security-osquery-api osquery-create-live-query cli command
Auth required
elastic stack kb security-osquery-api osquery-create-live-query [options]
Create a live query
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--agent-all- When
true, the query runs on all agents. --agent-idsstring[]- A list of agent IDs to run the query on.
--agent-platformsstring[]- A list of agent platforms to run the query on.
--agent-policy-idsstring[]- A list of agent policy IDs to run the query on.
--alert-idsstring[]- A list of alert IDs associated with the live query.
--case-idsstring[]- A list of case IDs associated with the live query.
--ecs-mappingstring--event-idsstring[]- A list of event IDs associated with the live query.
--metadatastring- Custom metadata object associated with the live query.
--pack-idstring--queriesstring[]--querystring--saved-query-idstring--input-filestring- path to a JSON file to use as command input
--dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--json-
output as JSON