stack kb security-osquery-api osquery-update-packs cli command
Auth required
Idempotent
Scope: global
elastic stack kb security-osquery-api osquery-update-packs --id <id> [options]
Update a pack
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--idstringrequired- The pack ID.
--descriptionstring--enabled--intervalnumber--min-osquery-versionstring--namestring--platformstring--policy-idsstring[]-
Repeatable: pass
--policy-idsmultiple times to supply more than one value --queriesstring--result-typeenum-
Values: snapshot, differential, differential_added_only
--rrule-schedulestring--schedule-typeenum-
Values: interval, rrule
--input-filestring- path to a JSON file to use as command input
--dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--no-validate- skip input validation and send the request as-is
--output-fieldsstring- comma-separated list of fields to include in output (dot-notation supported)
--output-templatestring- Mustache-like template for custom text output (e.g. "{{id}}: {{name}}")
--json-
output as JSON