Security Detections API

Create a detection rule

Spaces method and path for this operation:

<div><span class="operation-verb post">post</span>&nbsp;<span class="operation-path">/s/{space_id}/api/detection_engine/rules</span></div>

Refer to Spaces for more information.

Create a new detection rule.

warn When used with API key authentication, the user's key gets assigned to the affected rules. If the user's key gets deleted or the user becomes inactive, the rules will stop running.

If the API key that is used for authorization has different privileges than the key that created or most recently updated the rule, the rule behavior might change.

You can create the following types of rules:

  • Custom query: Searches the defined indices and creates an alert when a document matches the rule's KQL query.
  • Event correlation: Searches the defined indices and creates an alert when results match an Event Query Language (EQL) query.
  • Threshold: Searches the defined indices and creates an alert when the number of times the specified field's value meets the threshold during a single execution. When there are multiple values that meet the threshold, an alert is generated for each value. For example, if the threshold field is source.ip and its value is 10, an alert is generated for every source IP address that appears in at least 10 of the rule's search results. If you're interested, see Terms Aggregation for more information.
  • Indicator match: Creates an alert when fields match values defined in the specified Elasticsearch index. For example, you can create an index for IP addresses and use this index to create an alert whenever an event's destination.ip equals a value in the index. The index's field mappings should be ECS-compliant.
  • New terms: Generates an alert for each new term detected in source documents within a specified time range.
  • ES|QL: Uses Elasticsearch Query Language (ES|QL) to find events and aggregate search results.
  • Machine learning rules: Creates an alert when a machine learning job discovers an anomaly above the defined threshold.

info To create machine learning rules, you must have the appropriate license or use a cloud deployment. Additionally, for the machine learning rule to function correctly, the associated machine learning job must be running.

To retrieve machine learning job IDs, which are required to create machine learning jobs, call the Elasticsearch Get jobs API. Machine learning jobs that contain siem in the groups field can be used to create rules:

...
"job_id": "linux_anomalous_network_activity_ecs",
"job_type": "anomaly_detector",
"job_version": "7.7.0",
"groups": [
  "auditbeat",
  "process",
  "siem"
],
...

Additionally, you can set up notifications for when rules create alerts. The notifications use the Alerting and Actions framework. Each action type requires a connector. Connectors store the information required to send notifications via external systems. The following connector types are supported for rule notifications:

  • Slack
  • Email
  • PagerDuty
  • Webhook
  • Microsoft Teams
  • IBM Resilient
  • Jira
  • ServiceNow ITSM

info For more information on PagerDuty fields, see Send a v2 Event.

To retrieve connector IDs, which are required to configure rule notifications, call the Find objects API with "type": "action" in the request payload.

For detailed information on Kibana actions and alerting, and additional API calls, see:

post/api/detection_engine/rules

Request body

OR
OR
OR
OR
OR
OR
OR

Example request

{
  "actions": [
    {
      "frequency": {
        "throttle": "1h"
      }
    }
  ],
  "description": "Detects anomalous Windows process creation events.",
  "name": "Anomalous Windows Process Creation",
  "related_integrations": [
    {
      "integration": "activitylogs",
      "package": "azure",
      "version": "~1.1.6"
    }
  ],
  "response_actions": [
    {
      "params": {
        "config": {
          "linux": {
            "timeout": 60
          },
          "macos": {
            "timeout": 60
          },
          "windows": {
            "timeout": 60
          }
        }
      }
    }
  ],
  "throttle": "1h"
}

Response

Indicates a successful call.

OR
OR
OR
OR
OR
OR
OR

Example response

{
  "actions": [
    {
      "frequency": {
        "throttle": "1h"
      }
    }
  ],
  "description": "Detects anomalous Windows process creation events.",
  "name": "Anomalous Windows Process Creation",
  "related_integrations": [
    {
      "integration": "activitylogs",
      "package": "azure",
      "version": "~1.1.6"
    }
  ],
  "response_actions": [
    {
      "params": {
        "config": {
          "linux": {
            "timeout": 60
          },
          "macos": {
            "timeout": 60
          },
          "windows": {
            "timeout": 60
          }
        }
      }
    }
  ],
  "throttle": "1h"
}

Changes

Changed in 4 of the 176 revisions of this API.7219280

  • f2ad87b814123215232See the full diff
    • ▲

      removed subschema #1 subschema #2 from the ////////////// request property oneOf list

      request-property-one-of-removed

    • ▲

      removed subschema #1 subschema #2 from the //////////////// request property oneOf list

      request-property-one-of-removed

    • ▲

      removed subschema #1 subschema #2 from the ////////////// request property oneOf list

      request-property-one-of-removed

    • ▲

      removed subschema #1 subschema #2 from the //////////////// request property oneOf list

      request-property-one-of-removed

    • ▲

      removed subschema #1 subschema #2 from the ////////////// request property oneOf list

      request-property-one-of-removed

    • ▲

      removed subschema #1 subschema #2 from the //////////////// request property oneOf list

      request-property-one-of-removed

    • ▲

      removed subschema #1 subschema #2 from the ////////////// request property oneOf list

      request-property-one-of-removed

    • ▲

      removed subschema #1 subschema #2 from the //////////////// request property oneOf list

      request-property-one-of-removed

    • ▲

      removed subschema #1 subschema #2 from the ////////////// request property oneOf list

      request-property-one-of-removed

    • ▲

      removed subschema #1 subschema #2 from the //////////////// request property oneOf list

      request-property-one-of-removed

    • ▲

      removed subschema #1 subschema #2 from the ////////////// request property oneOf list

      request-property-one-of-removed

    • ▲

      removed subschema #1 subschema #2 from the //////////////// request property oneOf list

      request-property-one-of-removed

    • ▲

      removed subschema #1 subschema #2 from the ////////////// request property oneOf list

      request-property-one-of-removed

    • ▲

      removed subschema #1 subschema #2 from the //////////////// request property oneOf list

      request-property-one-of-removed

    • ▲

      removed subschema #1 subschema #2 from the ////////////// request property oneOf list

      request-property-one-of-removed

    • ▲

      removed subschema #1 subschema #2 from the //////////////// request property oneOf list

      request-property-one-of-removed

    • ▲

      added subschema #1 subschema #2 to the ////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added subschema #1 subschema #2 to the //////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added subschema #1 subschema #2 to the ////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added subschema #1 subschema #2 to the //////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added subschema #1 subschema #2 to the ////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added subschema #1 subschema #2 to the //////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added subschema #1 subschema #2 to the ////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added subschema #1 subschema #2 to the //////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added subschema #1 subschema #2 to the ////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added subschema #1 subschema #2 to the //////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added subschema #1 subschema #2 to the ////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added subschema #1 subschema #2 to the //////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added subschema #1 subschema #2 to the ////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added subschema #1 subschema #2 to the //////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added subschema #1 subschema #2 to the ////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added subschema #1 subschema #2 to the //////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ●

      the //////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the //////////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the //////////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the //////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 8192

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 8192

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 8192

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 2000

      request-property-max-length-set

    • ●

      the //////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the //////////////// request property's maxLength was set to 2000

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the //////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the //////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the //////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the //////////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the //////////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the //////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 8192

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 8192

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 8192

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 2000

      request-property-max-length-set

    • ●

      the //////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the //////////////// request property's maxLength was set to 2000

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the //////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the //////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the //////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the //////////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the //////////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the //////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 8192

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 8192

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 8192

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 2000

      request-property-max-length-set

    • ●

      the //////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the //////////////// request property's maxLength was set to 2000

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the //////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the //////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the //////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the //////////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the //////////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the //////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 8192

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 8192

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 8192

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 2000

      request-property-max-length-set

    • ●

      the //////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the //////////////// request property's maxLength was set to 2000

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the //////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the //////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the //////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the //////////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the //////////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the //////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 8192

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 8192

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 8192

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 2000

      request-property-max-length-set

    • ●

      the //////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the //////////////// request property's maxLength was set to 2000

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the //////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the //////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the //////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the //////////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the //////////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the //////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 8192

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 8192

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 8192

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 2000

      request-property-max-length-set

    • ●

      the //////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the //////////////// request property's maxLength was set to 2000

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the //////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the //////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the //////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the //////////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the //////////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the //////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 8192

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 8192

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 8192

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 2000

      request-property-max-length-set

    • ●

      the //////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the //////////////// request property's maxLength was set to 2000

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the //////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the //////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the //////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the //////////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the //////////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the //////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 8192

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 8192

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////////// request property's maxLength was set to 8192

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 2000

      request-property-max-length-set

    • ●

      the //////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the //////////////// request property's maxLength was set to 2000

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the ////////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ●

      the //////////// request property's maxLength was set to 30000

      request-property-max-length-set

    • ●

      the //////////// request property's maxLength was set to 256

      request-property-max-length-set

    • ○

      added subschema #1 subschema #2 to the ////////////// request property oneOf list

      request-property-one-of-added

    • ○

      added subschema #1 subschema #2 to the //////////////// request property oneOf list

      request-property-one-of-added

    • ○

      added subschema #1 subschema #2 to the ////////////// request property oneOf list

      request-property-one-of-added

    • ○

      added subschema #1 subschema #2 to the //////////////// request property oneOf list

      request-property-one-of-added

    • ○

      added subschema #1 subschema #2 to the ////////////// request property oneOf list

      request-property-one-of-added

    • ○

      added subschema #1 subschema #2 to the //////////////// request property oneOf list

      request-property-one-of-added

    • ○

      added subschema #1 subschema #2 to the ////////////// request property oneOf list

      request-property-one-of-added

    • ○

      added subschema #1 subschema #2 to the //////////////// request property oneOf list

      request-property-one-of-added

    • ○

      added subschema #1 subschema #2 to the ////////////// request property oneOf list

      request-property-one-of-added

    • ○

      added subschema #1 subschema #2 to the //////////////// request property oneOf list

      request-property-one-of-added

    • ○

      added subschema #1 subschema #2 to the ////////////// request property oneOf list

      request-property-one-of-added

    • ○

      added subschema #1 subschema #2 to the //////////////// request property oneOf list

      request-property-one-of-added

    • ○

      added subschema #1 subschema #2 to the ////////////// request property oneOf list

      request-property-one-of-added

    • ○

      added subschema #1 subschema #2 to the //////////////// request property oneOf list

      request-property-one-of-added

    • ○

      added subschema #1 subschema #2 to the ////////////// request property oneOf list

      request-property-one-of-added

    • ○

      added subschema #1 subschema #2 to the //////////////// request property oneOf list

      request-property-one-of-added

    • ○

      removed subschema #1 subschema #2 from the ////////////// response property oneOf list for the response status

      response-property-one-of-removed

    • ○

      removed subschema #1 subschema #2 from the //////////////// response property oneOf list for the response status

      response-property-one-of-removed

    • ○

      removed subschema #1 subschema #2 from the ////////////// response property oneOf list for the response status

      response-property-one-of-removed

    • ○

      removed subschema #1 subschema #2 from the //////////////// response property oneOf list for the response status

      response-property-one-of-removed

    • ○

      removed subschema #1 subschema #2 from the ////////////// response property oneOf list for the response status

      response-property-one-of-removed

    • ○

      removed subschema #1 subschema #2 from the //////////////// response property oneOf list for the response status

      response-property-one-of-removed

    • ○

      removed subschema #1 subschema #2 from the ////////////// response property oneOf list for the response status

      response-property-one-of-removed

    • ○

      removed subschema #1 subschema #2 from the //////////////// response property oneOf list for the response status

      response-property-one-of-removed

    • ○

      removed subschema #1 subschema #2 from the ////////////// response property oneOf list for the response status

      response-property-one-of-removed

    • ○

      removed subschema #1 subschema #2 from the //////////////// response property oneOf list for the response status

      response-property-one-of-removed

    • ○

      removed subschema #1 subschema #2 from the ////////////// response property oneOf list for the response status

      response-property-one-of-removed

    • ○

      removed subschema #1 subschema #2 from the //////////////// response property oneOf list for the response status

      response-property-one-of-removed

    • ○

      removed subschema #1 subschema #2 from the ////////////// response property oneOf list for the response status

      response-property-one-of-removed

    • ○

      removed subschema #1 subschema #2 from the //////////////// response property oneOf list for the response status

      response-property-one-of-removed

    • ○

      removed subschema #1 subschema #2 from the ////////////// response property oneOf list for the response status

      response-property-one-of-removed

    • ○

      removed subschema #1 subschema #2 from the //////////////// response property oneOf list for the response status

      response-property-one-of-removed

    • ○

      the request property default value 100 was removed

      request-property-default-value-removed

    • ○

      the request property default value 100 was removed

      request-property-default-value-removed

    • ○

      the request property default value 100 was removed

      request-property-default-value-removed

    • ○

      the request property default value 100 was removed

      request-property-default-value-removed

    • ○

      the request property default value 100 was removed

      request-property-default-value-removed

    • ○

      the request property default value 100 was removed

      request-property-default-value-removed

    • ○

      the request property default value 100 was removed

      request-property-default-value-removed

    • ○

      the request property default value 100 was removed

      request-property-default-value-removed

    • ○

      the response's property default value 100 was removed for the status

      response-property-default-value-removed

    • ○

      the response's property default value 100 was removed for the status

      response-property-default-value-removed

    • ○

      the response's property default value 100 was removed for the status

      response-property-default-value-removed

    • ○

      the response's property default value 100 was removed for the status

      response-property-default-value-removed

    • ○

      the response's property default value 100 was removed for the status

      response-property-default-value-removed

    • ○

      the response's property default value 100 was removed for the status

      response-property-default-value-removed

    • ○

      the response's property default value 100 was removed for the status

      response-property-default-value-removed

    • ○

      the response's property default value 100 was removed for the status

      response-property-default-value-removed

  • f418569a8423403224See the full diff
    • ▲

      the /////////////// request property type changed from object to no type

      request-property-type-changed

    • ▲

      the /////////////// request property type changed from object to no type

      request-property-type-changed

    • ▲

      the /////////////// request property type changed from object to no type

      request-property-type-changed

    • ▲

      the /////////////// request property type changed from object to no type

      request-property-type-changed

    • ▲

      the /////////////// request property type changed from object to no type

      request-property-type-changed

    • ▲

      the /////////////// request property type changed from object to no type

      request-property-type-changed

    • ▲

      the /////////////// request property type changed from object to no type

      request-property-type-changed

    • ▲

      the /////////////// request property type changed from object to no type

      request-property-type-changed

    • ▲

      added to the /////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added to the /////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added to the /////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added to the /////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added to the /////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added to the /////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added to the /////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      added to the /////////////// response property oneOf list for the response status

      response-property-one-of-added

    • ▲

      the /////////////// response's property type changed from object to no type for status

      response-property-type-changed

    • ▲

      the /////////////// response's property type changed from object to no type for status

      response-property-type-changed

    • ▲

      the /////////////// response's property type changed from object to no type for status

      response-property-type-changed

    • ▲

      the /////////////// response's property type changed from object to no type for status

      response-property-type-changed

    • ▲

      the /////////////// response's property type changed from object to no type for status

      response-property-type-changed

    • ▲

      the /////////////// response's property type changed from object to no type for status

      response-property-type-changed

    • ▲

      the /////////////// response's property type changed from object to no type for status

      response-property-type-changed

    • ▲

      the /////////////// response's property type changed from object to no type for status

      response-property-type-changed

    • ▲

      removed the required property //////////////// from the response with the status

      response-required-property-removed

    • ▲

      removed the required property //////////////// from the response with the status

      response-required-property-removed

    • ▲

      removed the required property //////////////// from the response with the status

      response-required-property-removed

    • ▲

      removed the required property //////////////// from the response with the status

      response-required-property-removed

    • ▲

      removed the required property //////////////// from the response with the status

      response-required-property-removed

    • ▲

      removed the required property //////////////// from the response with the status

      response-required-property-removed

    • ▲

      removed the required property //////////////// from the response with the status

      response-required-property-removed

    • ▲

      removed the required property //////////////// from the response with the status

      response-required-property-removed

    • ▲

      removed the required property //////////////// from the response with the status

      response-required-property-removed

    • ▲

      removed the required property //////////////// from the response with the status

      response-required-property-removed

    • ▲

      removed the required property //////////////// from the response with the status

      response-required-property-removed

    • ▲

      removed the required property //////////////// from the response with the status

      response-required-property-removed

    • ▲

      removed the required property //////////////// from the response with the status

      response-required-property-removed

    • ▲

      removed the required property //////////////// from the response with the status

      response-required-property-removed

    • ▲

      removed the required property //////////////// from the response with the status

      response-required-property-removed

    • ▲

      removed the required property //////////////// from the response with the status

      response-required-property-removed

    • ●

      removed the request property ////////////////

      request-property-removed

    • ●

      removed the request property ////////////////

      request-property-removed

    • ●

      removed the request property ////////////////

      request-property-removed

    • ●

      removed the request property ////////////////

      request-property-removed

    • ●

      removed the request property ////////////////

      request-property-removed

    • ●

      removed the request property ////////////////

      request-property-removed

    • ●

      removed the request property ////////////////

      request-property-removed

    • ●

      removed the request property ////////////////

      request-property-removed

    • ●

      removed the request property ////////////////

      request-property-removed

    • ●

      removed the request property ////////////////

      request-property-removed

    • ●

      removed the request property ////////////////

      request-property-removed

    • ●

      removed the request property ////////////////

      request-property-removed

    • ●

      removed the request property ////////////////

      request-property-removed

    • ●

      removed the request property ////////////////

      request-property-removed

    • ●

      removed the request property ////////////////

      request-property-removed

    • ●

      removed the request property ////////////////

      request-property-removed

    • ●

      removed the request property ////////////////

      request-property-removed

    • ●

      removed the request property ////////////////

      request-property-removed

    • ●

      removed the request property ////////////////

      request-property-removed

    • ●

      removed the request property ////////////////

      request-property-removed

    • ●

      removed the request property ////////////////

      request-property-removed

    • ●

      removed the request property ////////////////

      request-property-removed

    • ●

      removed the request property ////////////////

      request-property-removed

    • ●

      removed the request property ////////////////

      request-property-removed

    • ●

      removed the optional property //////////////// from the response with the status

      response-optional-property-removed

    • ●

      removed the optional property //////////////// from the response with the status

      response-optional-property-removed

    • ●

      removed the optional property //////////////// from the response with the status

      response-optional-property-removed

    • ●

      removed the optional property //////////////// from the response with the status

      response-optional-property-removed

    • ●

      removed the optional property //////////////// from the response with the status

      response-optional-property-removed

    • ●

      removed the optional property //////////////// from the response with the status

      response-optional-property-removed

    • ●

      removed the optional property //////////////// from the response with the status

      response-optional-property-removed

    • ●

      removed the optional property //////////////// from the response with the status

      response-optional-property-removed

    • ○

      added discriminator to /////////////// request property

      request-property-discriminator-added

    • ○

      added discriminator to /////////////// request property

      request-property-discriminator-added

    • ○

      added discriminator to /////////////// request property

      request-property-discriminator-added

    • ○

      added discriminator to /////////////// request property

      request-property-discriminator-added

    • ○

      added discriminator to /////////////// request property

      request-property-discriminator-added

    • ○

      added discriminator to /////////////// request property

      request-property-discriminator-added

    • ○

      added discriminator to /////////////// request property

      request-property-discriminator-added

    • ○

      added discriminator to /////////////// request property

      request-property-discriminator-added

    • ○

      added to the /////////////// request property oneOf list

      request-property-one-of-added

    • ○

      added to the /////////////// request property oneOf list

      request-property-one-of-added

    • ○

      added to the /////////////// request property oneOf list

      request-property-one-of-added

    • ○

      added to the /////////////// request property oneOf list

      request-property-one-of-added

    • ○

      added to the /////////////// request property oneOf list

      request-property-one-of-added

    • ○

      added to the /////////////// request property oneOf list

      request-property-one-of-added

    • ○

      added to the /////////////// request property oneOf list

      request-property-one-of-added

    • ○

      added to the /////////////// request property oneOf list

      request-property-one-of-added

    • ○

      added discriminator to /////////////// response property for the response status

      response-property-discriminator-added

    • ○

      added discriminator to /////////////// response property for the response status

      response-property-discriminator-added

    • ○

      added discriminator to /////////////// response property for the response status

      response-property-discriminator-added

    • ○

      added discriminator to /////////////// response property for the response status

      response-property-discriminator-added

    • ○

      added discriminator to /////////////// response property for the response status

      response-property-discriminator-added

    • ○

      added discriminator to /////////////// response property for the response status

      response-property-discriminator-added

    • ○

      added discriminator to /////////////// response property for the response status

      response-property-discriminator-added

    • ○

      added discriminator to /////////////// response property for the response status

      response-property-discriminator-added

    • ●

      added the new endpoint_custom_yara_signatures enum value to the /////// response property for the response status

      response-property-enum-value-added

    • ●

      added the new endpoint_custom_yara_signatures enum value to the /////// response property for the response status

      response-property-enum-value-added

    • ●

      added the new endpoint_custom_yara_signatures enum value to the /////// response property for the response status

      response-property-enum-value-added

    • ●

      added the new endpoint_custom_yara_signatures enum value to the /////// response property for the response status

      response-property-enum-value-added

    • ●

      added the new endpoint_custom_yara_signatures enum value to the /////// response property for the response status

      response-property-enum-value-added

    • ●

      added the new endpoint_custom_yara_signatures enum value to the /////// response property for the response status

      response-property-enum-value-added

    • ●

      added the new endpoint_custom_yara_signatures enum value to the /////// response property for the response status

      response-property-enum-value-added

    • ●

      added the new endpoint_custom_yara_signatures enum value to the /////// response property for the response status

      response-property-enum-value-added

    • ○

      added the new endpoint_custom_yara_signatures enum value to the request property ///////

      request-property-enum-value-added

    • ○

      added the new endpoint_custom_yara_signatures enum value to the request property ///////

      request-property-enum-value-added

    • ○

      added the new endpoint_custom_yara_signatures enum value to the request property ///////

      request-property-enum-value-added

    • ○

      added the new endpoint_custom_yara_signatures enum value to the request property ///////

      request-property-enum-value-added

    • ○

      added the new endpoint_custom_yara_signatures enum value to the request property ///////

      request-property-enum-value-added

    • ○

      added the new endpoint_custom_yara_signatures enum value to the request property ///////

      request-property-enum-value-added

    • ○

      added the new endpoint_custom_yara_signatures enum value to the request property ///////

      request-property-enum-value-added

    • ○

      added the new endpoint_custom_yara_signatures enum value to the request property ///////

      request-property-enum-value-added

Of the 176 revisions, 20 have no diff computed.