Security Detections API

Delete a detection rule

Spaces method and path for this operation:

<div><span class="operation-verb delete">delete</span>&nbsp;<span class="operation-path">/s/{space_id}/api/detection_engine/rules</span></div>

Refer to Spaces for more information.

Delete a detection rule using the rule_id or id field.

The URL query must include one of the following:

  • id - DELETE /api/detection_engine/rules?id=<id>
  • rule_id- DELETE /api/detection_engine/rules?rule_id=<rule_id>

The difference between the id and rule_id is that the id is a unique rule identifier that is randomly generated when a rule is created and cannot be set, whereas rule_id is a stable rule identifier that can be assigned during rule creation.

delete/api/detection_engine/rules

Query parameters

idstring uuid

A universally unique identifier

The rule's id value.

rule_idstring

A stable unique identifier for the rule object. It can be assigned during rule creation. It can be any string, but often is a UUID. It should be unique not only within a given Kibana space, but also across spaces and Elastic environments. The same prebuilt Elastic rule, when installed in two different Kibana spaces or two different Elastic environments, will have the same rule_ids.

The rule's rule_id value.

Response

Indicates a successful call.

OR
OR
OR
OR
OR
OR
OR

Example response

{
  "actions": [
    {
      "frequency": {
        "throttle": "1h"
      }
    }
  ],
  "description": "Detects anomalous Windows process creation events.",
  "name": "Anomalous Windows Process Creation",
  "related_integrations": [
    {
      "integration": "activitylogs",
      "package": "azure",
      "version": "~1.1.6"
    }
  ],
  "response_actions": [
    {
      "params": {
        "config": {
          "linux": {
            "timeout": 60
          },
          "macos": {
            "timeout": 60
          },
          "windows": {
            "timeout": 60
          }
        }
      }
    }
  ],
  "throttle": "1h"
}

Changes

Changed in 4 of the 176 revisions of this API.481632

  • f2ad87b814121616See the full diff
    • ▲

      added subschema #1 subschema #2 to the ////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added subschema #1 subschema #2 to the //////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added subschema #1 subschema #2 to the ////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added subschema #1 subschema #2 to the //////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added subschema #1 subschema #2 to the ////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added subschema #1 subschema #2 to the //////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added subschema #1 subschema #2 to the ////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added subschema #1 subschema #2 to the //////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added subschema #1 subschema #2 to the ////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added subschema #1 subschema #2 to the //////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added subschema #1 subschema #2 to the ////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added subschema #1 subschema #2 to the //////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added subschema #1 subschema #2 to the ////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added subschema #1 subschema #2 to the //////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added subschema #1 subschema #2 to the ////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added subschema #1 subschema #2 to the //////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ○

      removed subschema #1 subschema #2 from the ////////////// response property oneOf list for the response status

      response-property-one-of-removed

    • ○

      removed subschema #1 subschema #2 from the //////////////// response property oneOf list for the response status

      response-property-one-of-removed

    • ○

      removed subschema #1 subschema #2 from the ////////////// response property oneOf list for the response status

      response-property-one-of-removed

    • ○

      removed subschema #1 subschema #2 from the //////////////// response property oneOf list for the response status

      response-property-one-of-removed

    • ○

      removed subschema #1 subschema #2 from the ////////////// response property oneOf list for the response status

      response-property-one-of-removed

    • ○

      removed subschema #1 subschema #2 from the //////////////// response property oneOf list for the response status

      response-property-one-of-removed

    • ○

      removed subschema #1 subschema #2 from the ////////////// response property oneOf list for the response status

      response-property-one-of-removed

    • ○

      removed subschema #1 subschema #2 from the //////////////// response property oneOf list for the response status

      response-property-one-of-removed

    • ○

      removed subschema #1 subschema #2 from the ////////////// response property oneOf list for the response status

      response-property-one-of-removed

    • ○

      removed subschema #1 subschema #2 from the //////////////// response property oneOf list for the response status

      response-property-one-of-removed

    • ○

      removed subschema #1 subschema #2 from the ////////////// response property oneOf list for the response status

      response-property-one-of-removed

    • ○

      removed subschema #1 subschema #2 from the //////////////// response property oneOf list for the response status

      response-property-one-of-removed

    • ○

      removed subschema #1 subschema #2 from the ////////////// response property oneOf list for the response status

      response-property-one-of-removed

    • ○

      removed subschema #1 subschema #2 from the //////////////// response property oneOf list for the response status

      response-property-one-of-removed

    • ○

      removed subschema #1 subschema #2 from the ////////////// response property oneOf list for the response status

      response-property-one-of-removed

    • ○

      removed subschema #1 subschema #2 from the //////////////// response property oneOf list for the response status

      response-property-one-of-removed

    • ○

      the response's property default value 100 was removed for the status

      response-property-default-value-removed

    • ○

      the response's property default value 100 was removed for the status

      response-property-default-value-removed

    • ○

      the response's property default value 100 was removed for the status

      response-property-default-value-removed

    • ○

      the response's property default value 100 was removed for the status

      response-property-default-value-removed

    • ○

      the response's property default value 100 was removed for the status

      response-property-default-value-removed

    • ○

      the response's property default value 100 was removed for the status

      response-property-default-value-removed

    • ○

      the response's property default value 100 was removed for the status

      response-property-default-value-removed

    • ○

      the response's property default value 100 was removed for the status

      response-property-default-value-removed

  • f418569a84233288See the full diff
    • ▲

      added to the /////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added to the /////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added to the /////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added to the /////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added to the /////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added to the /////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added to the /////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added to the /////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      the /////////////// response's property type changed from object to no type for status

      response-property-type-changed

    • ▲

      the /////////////// response's property type changed from object to no type for status

      response-property-type-changed

    • ▲

      the /////////////// response's property type changed from object to no type for status

      response-property-type-changed

    • ▲

      the /////////////// response's property type changed from object to no type for status

      response-property-type-changed

    • ▲

      the /////////////// response's property type changed from object to no type for status

      response-property-type-changed

    • ▲

      the /////////////// response's property type changed from object to no type for status

      response-property-type-changed

    • ▲

      the /////////////// response's property type changed from object to no type for status

      response-property-type-changed

    • ▲

      the /////////////// response's property type changed from object to no type for status

      response-property-type-changed

    • ▲

      removed the required property //////////////// from the response with the status

      response-required-property-removed

    • ▲

      removed the required property //////////////// from the response with the status

      response-required-property-removed

    • ▲

      removed the required property //////////////// from the response with the status

      response-required-property-removed

    • ▲

      removed the required property //////////////// from the response with the status

      response-required-property-removed

    • ▲

      removed the required property //////////////// from the response with the status

      response-required-property-removed

    • ▲

      removed the required property //////////////// from the response with the status

      response-required-property-removed

    • ▲

      removed the required property //////////////// from the response with the status

      response-required-property-removed

    • ▲

      removed the required property //////////////// from the response with the status

      response-required-property-removed

    • ▲

      removed the required property //////////////// from the response with the status

      response-required-property-removed

    • ▲

      removed the required property //////////////// from the response with the status

      response-required-property-removed

    • ▲

      removed the required property //////////////// from the response with the status

      response-required-property-removed

    • ▲

      removed the required property //////////////// from the response with the status

      response-required-property-removed

    • ▲

      removed the required property //////////////// from the response with the status

      response-required-property-removed

    • ▲

      removed the required property //////////////// from the response with the status

      response-required-property-removed

    • ▲

      removed the required property //////////////// from the response with the status

      response-required-property-removed

    • ▲

      removed the required property //////////////// from the response with the status

      response-required-property-removed

    • ●

      removed the optional property //////////////// from the response with the status

      response-optional-property-removed

    • ●

      removed the optional property //////////////// from the response with the status

      response-optional-property-removed

    • ●

      removed the optional property //////////////// from the response with the status

      response-optional-property-removed

    • ●

      removed the optional property //////////////// from the response with the status

      response-optional-property-removed

    • ●

      removed the optional property //////////////// from the response with the status

      response-optional-property-removed

    • ●

      removed the optional property //////////////// from the response with the status

      response-optional-property-removed

    • ●

      removed the optional property //////////////// from the response with the status

      response-optional-property-removed

    • ●

      removed the optional property //////////////// from the response with the status

      response-optional-property-removed

    • ○

      added discriminator to /////////////// response property for the response status

      response-property-discriminator-added

    • ○

      added discriminator to /////////////// response property for the response status

      response-property-discriminator-added

    • ○

      added discriminator to /////////////// response property for the response status

      response-property-discriminator-added

    • ○

      added discriminator to /////////////// response property for the response status

      response-property-discriminator-added

    • ○

      added discriminator to /////////////// response property for the response status

      response-property-discriminator-added

    • ○

      added discriminator to /////////////// response property for the response status

      response-property-discriminator-added

    • ○

      added discriminator to /////////////// response property for the response status

      response-property-discriminator-added

    • ○

      added discriminator to /////////////// response property for the response status

      response-property-discriminator-added

    • ●

      added the new endpoint_custom_yara_signatures enum value to the /////// response property for the response status

      response-property-enum-value-added

    • ●

      added the new endpoint_custom_yara_signatures enum value to the /////// response property for the response status

      response-property-enum-value-added

    • ●

      added the new endpoint_custom_yara_signatures enum value to the /////// response property for the response status

      response-property-enum-value-added

    • ●

      added the new endpoint_custom_yara_signatures enum value to the /////// response property for the response status

      response-property-enum-value-added

    • ●

      added the new endpoint_custom_yara_signatures enum value to the /////// response property for the response status

      response-property-enum-value-added

    • ●

      added the new endpoint_custom_yara_signatures enum value to the /////// response property for the response status

      response-property-enum-value-added

    • ●

      added the new endpoint_custom_yara_signatures enum value to the /////// response property for the response status

      response-property-enum-value-added

    • ●

      added the new endpoint_custom_yara_signatures enum value to the /////// response property for the response status

      response-property-enum-value-added

Of the 176 revisions, 20 have no diff computed.