stack kb security-detections-api search-attacks cli command
Auth required
elastic stack kb security-detections-api search-attacks [options]
Find and/or aggregate attack discovery alerts
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--sourcestring-
Repeatable: pass
--sourcemultiple times to supply more than one value --aggsstring--fieldsstring[]-
Repeatable: pass
--fieldsmultiple times to supply more than one value --querystring--runtime-mappingsstring--sizenumber--sortstring-
Repeatable: pass
--sortmultiple times to supply more than one value --track-total-hits--input-filestring- path to a JSON file to use as command input
--dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--no-validate- skip input validation and send the request as-is
--output-fieldsstring- comma-separated list of fields to include in output (dot-notation supported)
--output-templatestring- Mustache-like template for custom text output (e.g. "{{id}}: {{name}}")
--json-
output as JSON