stack kb security-entity-analytics-api update-watchlist cli command
Auth required
Idempotent
Scope: global
elastic stack kb security-entity-analytics-api update-watchlist \
--id <id> \
--name <name> \
--risk-modifier <risk-modifier> \
[options]
Update an existing watchlist
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--idstringrequired- The ID of the watchlist to update
--namestringrequired- Unique name of the watchlist
--risk-modifiernumberrequired- Risk score modifier associated with the watchlist
--descriptionstring- Description of the watchlist
--managed- Indicates if the watchlist is managed by the system
--input-filestring- path to a JSON file to use as command input
--dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--json-
output as JSON