stack kb security-osquery-api osquery-find-live-queries cli command
Auth required
Idempotent
Scope: global
elastic stack kb security-osquery-api osquery-find-live-queries [options]
Get live queries
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--kuerystring- A KQL search string to filter live queries.
--pagestring- The page number to return.
--page-sizestring- The number of results to return per page.
--sortstring- The field to sort results by.
--sort-orderenum-
The sort order.
Values: asc, desc
--input-filestring- path to a JSON file to use as command input
--dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--json-
output as JSON