stack kb security-osquery-api osquery-delete-saved-query cli command
Destructive
Auth required
Idempotent
Scope: global
elastic stack kb security-osquery-api osquery-delete-saved-query \
--id <id> \
[options]
Delete a saved query
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--idstringrequired- The saved query ID.
--input-filestring- path to a JSON file to use as command input
--dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--yes- confirm destructive action without prompting
--json-
output as JSON