stack kb security-osquery-api osquery-find-live-queries cli command

Auth required Idempotent Scope: global
elastic stack kb security-osquery-api osquery-find-live-queries [options]
		

Get live queries

Behaviour flags:

--dry-run — validate all inputs and exit without performing any action

--kuery string
A KQL search string to filter live queries.
--page string
The page number to return.
--page-size string
The number of results to return per page.
--sort string
The field to sort results by.
--sort-order enum

The sort order.

Values: asc, desc

--input-file string
path to a JSON file to use as command input
--dry-run
validate all inputs and exit without performing any action (preview changes without applying them)
--json

output as JSON