stack kb security-detections-api set-alerts-status cli command

Auth required
elastic stack kb security-detections-api set-alerts-status \
  --status <status> \
  [options]
		

Set a detection alert status

Behaviour flags:

--dry-run — validate all inputs and exit without performing any action

--status enum required

Values: open, acknowledged, in-progress

--reason string
--signal-ids string[]

List of alert ids. Use field _id on alert document or kibana.alert.uuid. Note: signals are a deprecated term for alerts.

Repeatable: pass --signal-ids multiple times to supply more than one value

--conflicts enum

Values: abort, proceed

--query string
--runtime-fields string
Optional map of field name to runtime field type. For each entry, a runtime field of the specified type is created reading its value from _source[fieldName] and included in the query as runtime_mappings. Use this to reference fields stored on the alert _source that are not part of the Elastic Common Schema (ECS) of the alerts index mapping, for example, custom fields that the rule's source index defined when the alerts were created.
--runtime-mappings string
Use this when the query references fields that are not in the alerts index mapping, for example data view runtime fields with a Painless script. Kibana sends type, script.source, and format to Elasticsearch as runtime_mappings on the status-update query. Unlike runtime_fields, Kibana keeps your script and runs it at query time. It does not replace the script with a _source reader. When a script is present, Kibana sets on_script_error to continue. If the script fails on one alert, that field has no value for the alert and the update continues. Unique field names across runtime_fields and runtime_mappings combined cannot exceed 100. Larger maps are rejected.
--input-file string
path to a JSON file to use as command input
--dry-run
validate all inputs and exit without performing any action (preview changes without applying them)
--no-validate
skip input validation and send the request as-is
--output-fields string
comma-separated list of fields to include in output (dot-notation supported)
--output-template string
Mustache-like template for custom text output (e.g. "{{id}}: {{name}}")
--json

output as JSON