---
title: "Changes to Create a detection rule"
method: POST
path: "/api/detection_engine/rules"
---

# Changes to Create a detection rule

`POST /api/detection_engine/rules`

> Every recorded change to this endpoint, newest first.
> 176 revisions in range; 20 not diffed.

## Timeline

Changed in 4 of 176 revisions.

- **2026-09-09** `f2ad87b81412` — 32 breaking, 152 warning, 32 info
- **2026-08-26** `04c196070f95` — 16 info
- **2026-08-03** `f418569a8423` — 40 breaking, 32 warning, 24 info
- **2026-08-03** `707a2918b22b` — 8 warning, 8 info

## Changes

- **2026-09-09** `f2ad87b81412` — 32 breaking, 152 warning, 32 info
  - removed `subschema #1, subschema #2` from the `anyOf[#/components/schemas/Security_Detections_API_EqlRuleCreateProps]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_OsqueryResponseAction]/params/ecs_mapping/additionalProperties/value` request property `oneOf` list
  - removed `subschema #1, subschema #2` from the `anyOf[#/components/schemas/Security_Detections_API_EqlRuleCreateProps]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_OsqueryResponseAction]/params/queries/items/ecs_mapping/additionalProperties/value` request property `oneOf` list
  - removed `subschema #1, subschema #2` from the `anyOf[#/components/schemas/Security_Detections_API_EsqlRuleCreateProps]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_OsqueryResponseAction]/params/ecs_mapping/additionalProperties/value` request property `oneOf` list
  - removed `subschema #1, subschema #2` from the `anyOf[#/components/schemas/Security_Detections_API_EsqlRuleCreateProps]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_OsqueryResponseAction]/params/queries/items/ecs_mapping/additionalProperties/value` request property `oneOf` list
  - removed `subschema #1, subschema #2` from the `anyOf[#/components/schemas/Security_Detections_API_MachineLearningRuleCreateProps]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_OsqueryResponseAction]/params/ecs_mapping/additionalProperties/value` request property `oneOf` list
  - removed `subschema #1, subschema #2` from the `anyOf[#/components/schemas/Security_Detections_API_MachineLearningRuleCreateProps]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_OsqueryResponseAction]/params/queries/items/ecs_mapping/additionalProperties/value` request property `oneOf` list
  - removed `subschema #1, subschema #2` from the `anyOf[#/components/schemas/Security_Detections_API_NewTermsRuleCreateProps]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_OsqueryResponseAction]/params/ecs_mapping/additionalProperties/value` request property `oneOf` list
  - removed `subschema #1, subschema #2` from the `anyOf[#/components/schemas/Security_Detections_API_NewTermsRuleCreateProps]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_OsqueryResponseAction]/params/queries/items/ecs_mapping/additionalProperties/value` request property `oneOf` list
  - removed `subschema #1, subschema #2` from the `anyOf[#/components/schemas/Security_Detections_API_QueryRuleCreateProps]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_OsqueryResponseAction]/params/ecs_mapping/additionalProperties/value` request property `oneOf` list
  - removed `subschema #1, subschema #2` from the `anyOf[#/components/schemas/Security_Detections_API_QueryRuleCreateProps]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_OsqueryResponseAction]/params/queries/items/ecs_mapping/additionalProperties/value` request property `oneOf` list
  - removed `subschema #1, subschema #2` from the `anyOf[#/components/schemas/Security_Detections_API_SavedQueryRuleCreateProps]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_OsqueryResponseAction]/params/ecs_mapping/additionalProperties/value` request property `oneOf` list
  - removed `subschema #1, subschema #2` from the `anyOf[#/components/schemas/Security_Detections_API_SavedQueryRuleCreateProps]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_OsqueryResponseAction]/params/queries/items/ecs_mapping/additionalProperties/value` request property `oneOf` list
  - removed `subschema #1, subschema #2` from the `anyOf[#/components/schemas/Security_Detections_API_ThreatMatchRuleCreateProps]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_OsqueryResponseAction]/params/ecs_mapping/additionalProperties/value` request property `oneOf` list
  - removed `subschema #1, subschema #2` from the `anyOf[#/components/schemas/Security_Detections_API_ThreatMatchRuleCreateProps]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_OsqueryResponseAction]/params/queries/items/ecs_mapping/additionalProperties/value` request property `oneOf` list
  - removed `subschema #1, subschema #2` from the `anyOf[#/components/schemas/Security_Detections_API_ThresholdRuleCreateProps]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_OsqueryResponseAction]/params/ecs_mapping/additionalProperties/value` request property `oneOf` list
  - removed `subschema #1, subschema #2` from the `anyOf[#/components/schemas/Security_Detections_API_ThresholdRuleCreateProps]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_OsqueryResponseAction]/params/queries/items/ecs_mapping/additionalProperties/value` request property `oneOf` list
  - added `subschema #1, subschema #2` to the `anyOf[#/components/schemas/Security_Detections_API_EqlRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_OsqueryResponseAction]/params/ecs_mapping/additionalProperties/value` response property `oneOf` list for the response status `200`
  - added `subschema #1, subschema #2` to the `anyOf[#/components/schemas/Security_Detections_API_EqlRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_OsqueryResponseAction]/params/queries/items/ecs_mapping/additionalProperties/value` response property `oneOf` list for the response status `200`
  - added `subschema #1, subschema #2` to the `anyOf[#/components/schemas/Security_Detections_API_EsqlRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_OsqueryResponseAction]/params/ecs_mapping/additionalProperties/value` response property `oneOf` list for the response status `200`
  - added `subschema #1, subschema #2` to the `anyOf[#/components/schemas/Security_Detections_API_EsqlRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_OsqueryResponseAction]/params/queries/items/ecs_mapping/additionalProperties/value` response property `oneOf` list for the response status `200`
  - added `subschema #1, subschema #2` to the `anyOf[#/components/schemas/Security_Detections_API_MachineLearningRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_OsqueryResponseAction]/params/ecs_mapping/additionalProperties/value` response property `oneOf` list for the response status `200`
  - added `subschema #1, subschema #2` to the `anyOf[#/components/schemas/Security_Detections_API_MachineLearningRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_OsqueryResponseAction]/params/queries/items/ecs_mapping/additionalProperties/value` response property `oneOf` list for the response status `200`
  - added `subschema #1, subschema #2` to the `anyOf[#/components/schemas/Security_Detections_API_NewTermsRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_OsqueryResponseAction]/params/ecs_mapping/additionalProperties/value` response property `oneOf` list for the response status `200`
  - added `subschema #1, subschema #2` to the `anyOf[#/components/schemas/Security_Detections_API_NewTermsRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_OsqueryResponseAction]/params/queries/items/ecs_mapping/additionalProperties/value` response property `oneOf` list for the response status `200`
  - added `subschema #1, subschema #2` to the `anyOf[#/components/schemas/Security_Detections_API_QueryRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_OsqueryResponseAction]/params/ecs_mapping/additionalProperties/value` response property `oneOf` list for the response status `200`
  - added `subschema #1, subschema #2` to the `anyOf[#/components/schemas/Security_Detections_API_QueryRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_OsqueryResponseAction]/params/queries/items/ecs_mapping/additionalProperties/value` response property `oneOf` list for the response status `200`
  - added `subschema #1, subschema #2` to the `anyOf[#/components/schemas/Security_Detections_API_SavedQueryRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_OsqueryResponseAction]/params/ecs_mapping/additionalProperties/value` response property `oneOf` list for the response status `200`
  - added `subschema #1, subschema #2` to the `anyOf[#/components/schemas/Security_Detections_API_SavedQueryRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_OsqueryResponseAction]/params/queries/items/ecs_mapping/additionalProperties/value` response property `oneOf` list for the response status `200`
  - added `subschema #1, subschema #2` to the `anyOf[#/components/schemas/Security_Detections_API_ThreatMatchRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_OsqueryResponseAction]/params/ecs_mapping/additionalProperties/value` response property `oneOf` list for the response status `200`
  - added `subschema #1, subschema #2` to the `anyOf[#/components/schemas/Security_Detections_API_ThreatMatchRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_OsqueryResponseAction]/params/queries/items/ecs_mapping/additionalProperties/value` response property `oneOf` list for the response status `200`
  - added `subschema #1, subschema #2` to the `anyOf[#/components/schemas/Security_Detections_API_ThresholdRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_OsqueryResponseAction]/params/ecs_mapping/additionalProperties/value` response property `oneOf` list for the response status `200`
  - added `subschema #1, subschema #2` to the `anyOf[#/components/schemas/Security_Detections_API_ThresholdRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_OsqueryResponseAction]/params/queries/items/ecs_mapping/additionalProperties/value` response property `oneOf` list for the response status `200`
  - the `anyOf[#/components/schemas/Security_Detections_API_EqlRuleCreateProps]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_DefaultParams]/comment` request property's maxLength was set to `30000`
  - the `anyOf[#/components/schemas/Security_Detections_API_EqlRuleCreateProps]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/oneOf[#/components/schemas/Security_Detections_API_KillProcessParams]/comment` request property's maxLength was set to `30000`
  - the `anyOf[#/components/schemas/Security_Detections_API_EqlRuleCreateProps]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/oneOf[#/components/schemas/Security_Detections_API_SuspendProcessParams]/comment` request property's maxLength was set to `30000`
  - the `anyOf[#/components/schemas/Security_Detections_API_EqlRuleCreateProps]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_RunscriptParams]/comment` request property's maxLength was set to `30000`
  - the `anyOf[#/components/schemas/Security_Detections_API_EqlRuleCreateProps]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_RunscriptParams]/config/linux/scriptId` request property's maxLength was set to `256`
  - the `anyOf[#/components/schemas/Security_Detections_API_EqlRuleCreateProps]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_RunscriptParams]/config/linux/scriptInput` request property's maxLength was set to `8192`
  - the `anyOf[#/components/schemas/Security_Detections_API_EqlRuleCreateProps]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_RunscriptParams]/config/macos/scriptId` request property's maxLength was set to `256`
  - the `anyOf[#/components/schemas/Security_Detections_API_EqlRuleCreateProps]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_RunscriptParams]/config/macos/scriptInput` request property's maxLength was set to `8192`
  - …176 more
- **2026-08-26** `04c196070f95` — 16 info
  - the `max_signals` request property default value `100` was removed
  - the `max_signals` request property default value `100` was removed
  - the `max_signals` request property default value `100` was removed
  - the `max_signals` request property default value `100` was removed
  - the `max_signals` request property default value `100` was removed
  - the `max_signals` request property default value `100` was removed
  - the `max_signals` request property default value `100` was removed
  - the `max_signals` request property default value `100` was removed
  - the `max_signals` response's property default value `100` was removed for the status `200`
  - the `max_signals` response's property default value `100` was removed for the status `200`
  - the `max_signals` response's property default value `100` was removed for the status `200`
  - the `max_signals` response's property default value `100` was removed for the status `200`
  - the `max_signals` response's property default value `100` was removed for the status `200`
  - the `max_signals` response's property default value `100` was removed for the status `200`
  - the `max_signals` response's property default value `100` was removed for the status `200`
  - the `max_signals` response's property default value `100` was removed for the status `200`
- **2026-08-03** `f418569a8423` — 40 breaking, 32 warning, 24 info
  - the `anyOf[#/components/schemas/Security_Detections_API_EqlRuleCreateProps]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/` request property type changed from `object` to no type
  - the `anyOf[#/components/schemas/Security_Detections_API_EsqlRuleCreateProps]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/` request property type changed from `object` to no type
  - the `anyOf[#/components/schemas/Security_Detections_API_MachineLearningRuleCreateProps]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/` request property type changed from `object` to no type
  - the `anyOf[#/components/schemas/Security_Detections_API_NewTermsRuleCreateProps]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/` request property type changed from `object` to no type
  - the `anyOf[#/components/schemas/Security_Detections_API_QueryRuleCreateProps]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/` request property type changed from `object` to no type
  - the `anyOf[#/components/schemas/Security_Detections_API_SavedQueryRuleCreateProps]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/` request property type changed from `object` to no type
  - the `anyOf[#/components/schemas/Security_Detections_API_ThreatMatchRuleCreateProps]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/` request property type changed from `object` to no type
  - the `anyOf[#/components/schemas/Security_Detections_API_ThresholdRuleCreateProps]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/` request property type changed from `object` to no type
  - added `#/components/schemas/Security_Detections_API_KillProcessParams, #/components/schemas/Security_Detections_API_SuspendProcessParams` to the `anyOf[#/components/schemas/Security_Detections_API_EqlRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/` response property `oneOf` list for the response status `200`
  - added `#/components/schemas/Security_Detections_API_KillProcessParams, #/components/schemas/Security_Detections_API_SuspendProcessParams` to the `anyOf[#/components/schemas/Security_Detections_API_EsqlRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/` response property `oneOf` list for the response status `200`
  - added `#/components/schemas/Security_Detections_API_KillProcessParams, #/components/schemas/Security_Detections_API_SuspendProcessParams` to the `anyOf[#/components/schemas/Security_Detections_API_MachineLearningRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/` response property `oneOf` list for the response status `200`
  - added `#/components/schemas/Security_Detections_API_KillProcessParams, #/components/schemas/Security_Detections_API_SuspendProcessParams` to the `anyOf[#/components/schemas/Security_Detections_API_NewTermsRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/` response property `oneOf` list for the response status `200`
  - added `#/components/schemas/Security_Detections_API_KillProcessParams, #/components/schemas/Security_Detections_API_SuspendProcessParams` to the `anyOf[#/components/schemas/Security_Detections_API_QueryRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/` response property `oneOf` list for the response status `200`
  - added `#/components/schemas/Security_Detections_API_KillProcessParams, #/components/schemas/Security_Detections_API_SuspendProcessParams` to the `anyOf[#/components/schemas/Security_Detections_API_SavedQueryRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/` response property `oneOf` list for the response status `200`
  - added `#/components/schemas/Security_Detections_API_KillProcessParams, #/components/schemas/Security_Detections_API_SuspendProcessParams` to the `anyOf[#/components/schemas/Security_Detections_API_ThreatMatchRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/` response property `oneOf` list for the response status `200`
  - added `#/components/schemas/Security_Detections_API_KillProcessParams, #/components/schemas/Security_Detections_API_SuspendProcessParams` to the `anyOf[#/components/schemas/Security_Detections_API_ThresholdRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/` response property `oneOf` list for the response status `200`
  - the `anyOf[#/components/schemas/Security_Detections_API_EqlRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/` response's property type changed from `object` to no type for status `200`
  - the `anyOf[#/components/schemas/Security_Detections_API_EsqlRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/` response's property type changed from `object` to no type for status `200`
  - the `anyOf[#/components/schemas/Security_Detections_API_MachineLearningRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/` response's property type changed from `object` to no type for status `200`
  - the `anyOf[#/components/schemas/Security_Detections_API_NewTermsRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/` response's property type changed from `object` to no type for status `200`
  - the `anyOf[#/components/schemas/Security_Detections_API_QueryRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/` response's property type changed from `object` to no type for status `200`
  - the `anyOf[#/components/schemas/Security_Detections_API_SavedQueryRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/` response's property type changed from `object` to no type for status `200`
  - the `anyOf[#/components/schemas/Security_Detections_API_ThreatMatchRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/` response's property type changed from `object` to no type for status `200`
  - the `anyOf[#/components/schemas/Security_Detections_API_ThresholdRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/` response's property type changed from `object` to no type for status `200`
  - removed the required property `anyOf[#/components/schemas/Security_Detections_API_EqlRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/command` from the response with the `200` status
  - removed the required property `anyOf[#/components/schemas/Security_Detections_API_EqlRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/config` from the response with the `200` status
  - removed the required property `anyOf[#/components/schemas/Security_Detections_API_EsqlRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/command` from the response with the `200` status
  - removed the required property `anyOf[#/components/schemas/Security_Detections_API_EsqlRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/config` from the response with the `200` status
  - removed the required property `anyOf[#/components/schemas/Security_Detections_API_MachineLearningRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/command` from the response with the `200` status
  - removed the required property `anyOf[#/components/schemas/Security_Detections_API_MachineLearningRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/config` from the response with the `200` status
  - removed the required property `anyOf[#/components/schemas/Security_Detections_API_NewTermsRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/command` from the response with the `200` status
  - removed the required property `anyOf[#/components/schemas/Security_Detections_API_NewTermsRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/config` from the response with the `200` status
  - removed the required property `anyOf[#/components/schemas/Security_Detections_API_QueryRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/command` from the response with the `200` status
  - removed the required property `anyOf[#/components/schemas/Security_Detections_API_QueryRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/config` from the response with the `200` status
  - removed the required property `anyOf[#/components/schemas/Security_Detections_API_SavedQueryRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/command` from the response with the `200` status
  - removed the required property `anyOf[#/components/schemas/Security_Detections_API_SavedQueryRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/config` from the response with the `200` status
  - removed the required property `anyOf[#/components/schemas/Security_Detections_API_ThreatMatchRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/command` from the response with the `200` status
  - removed the required property `anyOf[#/components/schemas/Security_Detections_API_ThreatMatchRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/config` from the response with the `200` status
  - removed the required property `anyOf[#/components/schemas/Security_Detections_API_ThresholdRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/command` from the response with the `200` status
  - removed the required property `anyOf[#/components/schemas/Security_Detections_API_ThresholdRule]/allOf[subschema #1]/response_actions/items/oneOf[#/components/schemas/Security_Detections_API_EndpointResponseAction]/params/oneOf[#/components/schemas/Security_Detections_API_ProcessesParams]/config` from the response with the `200` status
  - …56 more
- **2026-08-03** `707a2918b22b` — 8 warning, 8 info
  - added the new `endpoint_custom_yara_signatures` enum value to the `anyOf[#/components/schemas/Security_Detections_API_EqlRule]/allOf[subschema #1]/exceptions_list/items/type` response property for the response status `200`
  - added the new `endpoint_custom_yara_signatures` enum value to the `anyOf[#/components/schemas/Security_Detections_API_EsqlRule]/allOf[subschema #1]/exceptions_list/items/type` response property for the response status `200`
  - added the new `endpoint_custom_yara_signatures` enum value to the `anyOf[#/components/schemas/Security_Detections_API_MachineLearningRule]/allOf[subschema #1]/exceptions_list/items/type` response property for the response status `200`
  - added the new `endpoint_custom_yara_signatures` enum value to the `anyOf[#/components/schemas/Security_Detections_API_NewTermsRule]/allOf[subschema #1]/exceptions_list/items/type` response property for the response status `200`
  - added the new `endpoint_custom_yara_signatures` enum value to the `anyOf[#/components/schemas/Security_Detections_API_QueryRule]/allOf[subschema #1]/exceptions_list/items/type` response property for the response status `200`
  - added the new `endpoint_custom_yara_signatures` enum value to the `anyOf[#/components/schemas/Security_Detections_API_SavedQueryRule]/allOf[subschema #1]/exceptions_list/items/type` response property for the response status `200`
  - added the new `endpoint_custom_yara_signatures` enum value to the `anyOf[#/components/schemas/Security_Detections_API_ThreatMatchRule]/allOf[subschema #1]/exceptions_list/items/type` response property for the response status `200`
  - added the new `endpoint_custom_yara_signatures` enum value to the `anyOf[#/components/schemas/Security_Detections_API_ThresholdRule]/allOf[subschema #1]/exceptions_list/items/type` response property for the response status `200`
  - added the new `endpoint_custom_yara_signatures` enum value to the request property `anyOf[#/components/schemas/Security_Detections_API_EqlRuleCreateProps]/allOf[subschema #1]/exceptions_list/items/type`
  - added the new `endpoint_custom_yara_signatures` enum value to the request property `anyOf[#/components/schemas/Security_Detections_API_EsqlRuleCreateProps]/allOf[subschema #1]/exceptions_list/items/type`
  - added the new `endpoint_custom_yara_signatures` enum value to the request property `anyOf[#/components/schemas/Security_Detections_API_MachineLearningRuleCreateProps]/allOf[subschema #1]/exceptions_list/items/type`
  - added the new `endpoint_custom_yara_signatures` enum value to the request property `anyOf[#/components/schemas/Security_Detections_API_NewTermsRuleCreateProps]/allOf[subschema #1]/exceptions_list/items/type`
  - added the new `endpoint_custom_yara_signatures` enum value to the request property `anyOf[#/components/schemas/Security_Detections_API_QueryRuleCreateProps]/allOf[subschema #1]/exceptions_list/items/type`
  - added the new `endpoint_custom_yara_signatures` enum value to the request property `anyOf[#/components/schemas/Security_Detections_API_SavedQueryRuleCreateProps]/allOf[subschema #1]/exceptions_list/items/type`
  - added the new `endpoint_custom_yara_signatures` enum value to the request property `anyOf[#/components/schemas/Security_Detections_API_ThreatMatchRuleCreateProps]/allOf[subschema #1]/exceptions_list/items/type`
  - added the new `endpoint_custom_yara_signatures` enum value to the request property `anyOf[#/components/schemas/Security_Detections_API_ThresholdRuleCreateProps]/allOf[subschema #1]/exceptions_list/items/type`

---

[Operation](https://skmtc.dev/elastic/apis/kibana-apis/docs/api/detection_engine/rules/post.md) · [API](https://skmtc.dev/elastic/apis/kibana-apis.md) · [Page](https://skmtc.dev/elastic/apis/kibana-apis/changes/api/detection_engine/rules/post)
