stack kb significantevents put-streams-name-queries-queryid cli command
Auth required
Idempotent
Scope: global
elastic stack kb significantevents put-streams-name-queries-queryid \
--name <name> \
--query-id <query-id> \
--esql <esql> \
--title <title> \
[options]
Upsert a query to a stream
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--namestringrequired- The name of the stream.
--query-idstringrequired- The identifier of the query.
--esqlstringrequired--titlestringrequired- A non-empty string.
--descriptionstring--evidencestring[]--expires-atstring--severity-scorenumber--input-filestring- path to a JSON file to use as command input
--dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--json-
output as JSON