stack kb security-detections-api set-alerts-status cli command
Auth required
elastic stack kb security-detections-api set-alerts-status \
--status <status> \
[options]
Set a detection alert status
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--statusenumrequired-
Values: open, acknowledged, in-progress
--reasonstring--signal-idsstring[]-
List of alert ids. Use field
_idon alert document orkibana.alert.uuid. Note: signals are a deprecated term for alerts.Repeatable: pass
--signal-idsmultiple times to supply more than one value --conflictsenum-
Values: abort, proceed
--querystring--runtime-fieldsstring- Optional map of field name to runtime field type. For each entry, a runtime field of the specified type is created reading its value from
_source[fieldName]and included in the query asruntime_mappings. Use this to reference fields stored on the alert_sourcethat are not part of the Elastic Common Schema (ECS) of the alerts index mapping, for example, custom fields that the rule's source index defined when the alerts were created. --runtime-mappingsstring- Use this when the query references fields that are not in the alerts index mapping, for example data view runtime fields with a Painless script.
Kibana sends
type,script.source, andformatto Elasticsearch asruntime_mappingson the status-update query. Unlikeruntime_fields, Kibana keeps your script and runs it at query time. It does not replace the script with a_sourcereader. When a script is present, Kibana setson_script_errortocontinue. If the script fails on one alert, that field has no value for the alert and the update continues. Unique field names acrossruntime_fieldsandruntime_mappingscombined cannot exceed 100. Larger maps are rejected. --input-filestring- path to a JSON file to use as command input
--dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--no-validate- skip input validation and send the request as-is
--output-fieldsstring- comma-separated list of fields to include in output (dot-notation supported)
--output-templatestring- Mustache-like template for custom text output (e.g. "{{id}}: {{name}}")
--json-
output as JSON