8 structure changes including:
    
    8 Modifications
        Modified
        8
          Breaking
      
      DELETE /api/detection_engine/rules
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
GET /api/detection_engine/rules
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
GET /api/detection_engine/rules/_find
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  data property Modified
    
- EqlRuleResponseFields, QueryRuleResponseFields, SavedQueryRuleResponseFields, ThresholdRuleResponseFields, ThreatMatchRuleResponseFields, MachineLearningRuleResponseFields, NewTermsRuleResponseFields, EsqlRuleResponseFields alternatives Modified
 
 
 - 
  data property Modified
    
 
 - 
  application/json content type Modified
    
 
PATCH /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- 
  jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek property Removed
    
 
 - 
  actions property Modified
    
 - 
  QueryRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- 
  jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek property Removed
    
 
 - 
  actions property Modified
    
 - 
  SavedQueryRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- 
  jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek property Removed
    
 
 - 
  actions property Modified
    
 - 
  ThresholdRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- 
  jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek property Removed
    
 
 - 
  actions property Modified
    
 - 
  ThreatMatchRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- 
  jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek property Removed
    
 
 - 
  actions property Modified
    
 - 
  MachineLearningRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- 
  jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek property Removed
    
 
 - 
  actions property Modified
    
 - 
  NewTermsRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- 
  jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek property Removed
    
 
 - 
  actions property Modified
    
 - 
  EsqlRulePatchProps alternative Modified
    
- 
  actions property Modified
    
- 
  jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek property Removed
    
 
 - 
  actions property Modified
    
 
 - 
  EqlRulePatchFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- 
  jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek property Removed
    
 
 - 
  actions property Modified
    
 - 
  QueryRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- 
  jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek property Removed
    
 
 - 
  actions property Modified
    
 - 
  SavedQueryRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- 
  jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek property Removed
    
 
 - 
  actions property Modified
    
 - 
  ThresholdRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- 
  jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek property Removed
    
 
 - 
  actions property Modified
    
 - 
  ThreatMatchRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- 
  jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek property Removed
    
 
 - 
  actions property Modified
    
 - 
  MachineLearningRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- 
  jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek property Removed
    
 
 - 
  actions property Modified
    
 - 
  NewTermsRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- 
  jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek property Removed
    
 
 - 
  actions property Modified
    
 - 
  EsqlRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- 
  jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek property Removed
    
 
 - 
  actions property Modified
    
 
 - 
  EqlRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/_bulk_action
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  BulkEditActionResponse alternative Modified
    
- attributes property Modified
 
 
 - 
  BulkEditActionResponse alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/preview
              - Body
 - 
  application/json content type Modified
    
- 
  RulePreviewParams alternative Modified
    
- 
  actions property Modified
    
- 
  jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek property Removed
    
 - data_view_id, event_category_override, filters, index, tiebreaker_field, timestamp_field properties Added
 
 - 
  actions property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  actions property Modified
    
- 
  jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek property Removed
    
 - 
  language, query properties Modified
    
- Properties are no longer required
 
 - data_view_id, filters, index, saved_id properties Added
 
 - 
  actions property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  actions property Modified
    
- 
  jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek property Removed
    
 - 
  query, language properties Modified
    
- Properties are no longer required
 
 - saved_id, data_view_id, filters, index properties Added
 
 - 
  actions property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  actions property Modified
    
- 
  jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek property Removed
    
 - 
  alert_suppression property Modified
    
- 
  duration property Modified
    
- 
          Property is now required Breaking
 
 - 
          Property is now required 
 - 
  group_by, missing_fields_strategy properties Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  duration property Modified
    
 - 
  language property Modified
    
- Property is no longer required
 
 - threshold, data_view_id, filters, index, saved_id properties Added
 
 - 
  actions property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  actions property Modified
    
- 
  jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek property Removed
    
 - 
  language property Modified
    
- Property is no longer required
 
 - threat_index, threat_mapping, threat_query, concurrent_searches, data_view_id, filters, index, items_per_search, saved_id, threat_filters, threat_indicator_path, threat_language properties Added
 
 - 
  actions property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  actions property Modified
    
- 
  jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek property Removed
    
 - 
  language, query properties Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - anomaly_threshold, array-2 properties Added
 
 - 
  actions property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  actions property Modified
    
- 
  jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek property Removed
    
 - 
  language property Modified
    
- Property is no longer required
 
 - history_window_start, new_terms_fields, data_view_id, filters, index properties Added
 
 - 
  actions property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  actions property Modified
    
- 
  jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek property Removed
    
 
 - 
  actions property Modified
    
 
 - 
  RulePreviewParams alternative Modified
    
 
PUT /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- 
  jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek property Removed
    
 
 - 
  actions property Modified
    
 - 
  QueryRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- 
  jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek property Removed
    
 
 - 
  actions property Modified
    
 - 
  SavedQueryRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- 
  jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek property Removed
    
 
 - 
  actions property Modified
    
 - 
  ThresholdRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- 
  jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek property Removed
    
 
 - 
  actions property Modified
    
 - 
  ThreatMatchRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- 
  jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek property Removed
    
 
 - 
  actions property Modified
    
 - 
  MachineLearningRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- 
  jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek property Removed
    
 
 - 
  actions property Modified
    
 - 
  NewTermsRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- 
  jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek property Removed
    
 
 - 
  actions property Modified
    
 - 
  EsqlRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- 
  jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek property Removed
    
 
 - 
  actions property Modified
    
 
 - 
  EqlRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
  8 structure changes including:
    
    8 Modifications
        Modified
        8
          Breaking
      
      DELETE /api/detection_engine/rules
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
GET /api/detection_engine/rules
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
GET /api/detection_engine/rules/_find
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  data property Modified
    
- EqlRuleResponseFields, QueryRuleResponseFields, SavedQueryRuleResponseFields, ThresholdRuleResponseFields, ThreatMatchRuleResponseFields, MachineLearningRuleResponseFields, NewTermsRuleResponseFields, EsqlRuleResponseFields alternatives Modified
 
 
 - 
  data property Modified
    
 
 - 
  application/json content type Modified
    
 
PATCH /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- jacek property Added
 
 
 - 
  actions property Modified
    
 - 
  QueryRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- jacek property Added
 
 
 - 
  actions property Modified
    
 - 
  SavedQueryRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- jacek property Added
 
 
 - 
  actions property Modified
    
 - 
  ThresholdRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- jacek property Added
 
 
 - 
  actions property Modified
    
 - 
  ThreatMatchRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- jacek property Added
 
 
 - 
  actions property Modified
    
 - 
  MachineLearningRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- jacek property Added
 
 
 - 
  actions property Modified
    
 - 
  NewTermsRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- jacek property Added
 
 
 - 
  actions property Modified
    
 - 
  EsqlRulePatchProps alternative Modified
    
- 
  actions property Modified
    
- jacek property Added
 
 
 - 
  actions property Modified
    
 
 - 
  EqlRulePatchFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- jacek property Added
 
 
 - 
  actions property Modified
    
 - 
  QueryRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- jacek property Added
 
 
 - 
  actions property Modified
    
 - 
  SavedQueryRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- jacek property Added
 
 
 - 
  actions property Modified
    
 - 
  ThresholdRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- jacek property Added
 
 
 - 
  actions property Modified
    
 - 
  ThreatMatchRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- jacek property Added
 
 
 - 
  actions property Modified
    
 - 
  MachineLearningRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- jacek property Added
 
 
 - 
  actions property Modified
    
 - 
  NewTermsRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- jacek property Added
 
 
 - 
  actions property Modified
    
 - 
  EsqlRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- jacek property Added
 
 
 - 
  actions property Modified
    
 
 - 
  EqlRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/_bulk_action
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  BulkEditActionResponse alternative Modified
    
- attributes property Modified
 
 
 - 
  BulkEditActionResponse alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/preview
              - Body
 - 
  application/json content type Modified
    
- 
  RulePreviewParams alternative Modified
    
- 
  actions property Modified
    
- jacek property Added
 
 - data_view_id, event_category_override, filters, index, tiebreaker_field, timestamp_field properties Added
 
 - 
  actions property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  actions property Modified
    
- jacek property Added
 
 - 
  language, query properties Modified
    
- Properties are no longer required
 
 - data_view_id, filters, index, saved_id properties Added
 
 - 
  actions property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  actions property Modified
    
- jacek property Added
 
 - 
  query, language properties Modified
    
- Properties are no longer required
 
 - saved_id, data_view_id, filters, index properties Added
 
 - 
  actions property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  actions property Modified
    
- jacek property Added
 
 - 
  alert_suppression property Modified
    
- 
  duration property Modified
    
- 
          Property is now required Breaking
 
 - 
          Property is now required 
 - 
  group_by, missing_fields_strategy properties Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  duration property Modified
    
 - 
  language property Modified
    
- Property is no longer required
 
 - threshold, data_view_id, filters, index, saved_id properties Added
 
 - 
  actions property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  actions property Modified
    
- jacek property Added
 
 - 
  language property Modified
    
- Property is no longer required
 
 - threat_index, threat_mapping, threat_query, concurrent_searches, data_view_id, filters, index, items_per_search, saved_id, threat_filters, threat_indicator_path, threat_language properties Added
 
 - 
  actions property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  actions property Modified
    
- jacek property Added
 
 - 
  language, query properties Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - anomaly_threshold, array-2 properties Added
 
 - 
  actions property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  actions property Modified
    
- jacek property Added
 
 - 
  language property Modified
    
- Property is no longer required
 
 - history_window_start, new_terms_fields, data_view_id, filters, index properties Added
 
 - 
  actions property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  actions property Modified
    
- jacek property Added
 
 
 - 
  actions property Modified
    
 
 - 
  RulePreviewParams alternative Modified
    
 
PUT /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- jacek property Added
 
 
 - 
  actions property Modified
    
 - 
  QueryRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- jacek property Added
 
 
 - 
  actions property Modified
    
 - 
  SavedQueryRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- jacek property Added
 
 
 - 
  actions property Modified
    
 - 
  ThresholdRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- jacek property Added
 
 
 - 
  actions property Modified
    
 - 
  ThreatMatchRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- jacek property Added
 
 
 - 
  actions property Modified
    
 - 
  MachineLearningRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- jacek property Added
 
 
 - 
  actions property Modified
    
 - 
  NewTermsRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- jacek property Added
 
 
 - 
  actions property Modified
    
 - 
  EsqlRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- jacek property Added
 
 
 - 
  actions property Modified
    
 
 - 
  EqlRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
  8 structure changes including:
    
    8 Modifications
        Modified
        8
          Breaking
      
      DELETE /api/detection_engine/rules
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
GET /api/detection_engine/rules
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
GET /api/detection_engine/rules/_find
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  data property Modified
    
- EqlRuleResponseFields, QueryRuleResponseFields, SavedQueryRuleResponseFields, ThresholdRuleResponseFields, ThreatMatchRuleResponseFields, MachineLearningRuleResponseFields, NewTermsRuleResponseFields, EsqlRuleResponseFields alternatives Modified
 
 
 - 
  data property Modified
    
 
 - 
  application/json content type Modified
    
 
PATCH /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRulePatchFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id property Added
 
 - 
  list_id_jacek property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  QueryRulePatchFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id property Added
 
 - 
  list_id_jacek property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  SavedQueryRulePatchFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id property Added
 
 - 
  list_id_jacek property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  ThresholdRulePatchFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id property Added
 
 - 
  list_id_jacek property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  ThreatMatchRulePatchFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id property Added
 
 - 
  list_id_jacek property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  MachineLearningRulePatchFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id property Added
 
 - 
  list_id_jacek property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  NewTermsRulePatchFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id property Added
 
 - 
  list_id_jacek property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  EsqlRulePatchProps alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id property Added
 
 - 
  list_id_jacek property Removed
    
 
 - 
  exceptions_list property Modified
    
 
 - 
  EqlRulePatchFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRuleCreateFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id property Added
 
 - 
  list_id_jacek property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  QueryRuleCreateFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id property Added
 
 - 
  list_id_jacek property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  SavedQueryRuleCreateFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id property Added
 
 - 
  list_id_jacek property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  ThresholdRuleCreateFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id property Added
 
 - 
  list_id_jacek property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  ThreatMatchRuleCreateFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id property Added
 
 - 
  list_id_jacek property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  MachineLearningRuleCreateFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id property Added
 
 - 
  list_id_jacek property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  NewTermsRuleCreateFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id property Added
 
 - 
  list_id_jacek property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  EsqlRuleCreateFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id property Added
 
 - 
  list_id_jacek property Removed
    
 
 - 
  exceptions_list property Modified
    
 
 - 
  EqlRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/_bulk_action
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  BulkEditActionResponse alternative Modified
    
- attributes property Modified
 
 
 - 
  BulkEditActionResponse alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/preview
              - Body
 - 
  application/json content type Modified
    
- 
  RulePreviewParams alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id property Added
 
 - 
  list_id_jacek property Removed
    
 - data_view_id, event_category_override, filters, index, tiebreaker_field, timestamp_field properties Added
 
 - 
  exceptions_list property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id property Added
 
 - 
  list_id_jacek property Removed
    
 - 
  language, query properties Modified
    
- Properties are no longer required
 
 - data_view_id, filters, index, saved_id properties Added
 
 - 
  exceptions_list property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id property Added
 
 - 
  list_id_jacek property Removed
    
 - 
  query, language properties Modified
    
- Properties are no longer required
 
 - saved_id, data_view_id, filters, index properties Added
 
 - 
  exceptions_list property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id property Added
 
 - 
  list_id_jacek property Removed
    
 - 
  alert_suppression property Modified
    
- 
  duration property Modified
    
- 
          Property is now required Breaking
 
 - 
          Property is now required 
 - 
  group_by, missing_fields_strategy properties Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  duration property Modified
    
 - 
  language property Modified
    
- Property is no longer required
 
 - threshold, data_view_id, filters, index, saved_id properties Added
 
 - 
  exceptions_list property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id property Added
 
 - 
  list_id_jacek property Removed
    
 - 
  language property Modified
    
- Property is no longer required
 
 - threat_index, threat_mapping, threat_query, concurrent_searches, data_view_id, filters, index, items_per_search, saved_id, threat_filters, threat_indicator_path, threat_language properties Added
 
 - 
  exceptions_list property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id property Added
 
 - 
  list_id_jacek property Removed
    
 - 
  language, query properties Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - anomaly_threshold, array-2 properties Added
 
 - 
  exceptions_list property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id property Added
 
 - 
  list_id_jacek property Removed
    
 - 
  language property Modified
    
- Property is no longer required
 
 - history_window_start, new_terms_fields, data_view_id, filters, index properties Added
 
 - 
  exceptions_list property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id property Added
 
 - 
  list_id_jacek property Removed
    
 
 - 
  exceptions_list property Modified
    
 
 - 
  RulePreviewParams alternative Modified
    
 
PUT /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRuleCreateFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id property Added
 
 - 
  list_id_jacek property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  QueryRuleCreateFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id property Added
 
 - 
  list_id_jacek property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  SavedQueryRuleCreateFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id property Added
 
 - 
  list_id_jacek property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  ThresholdRuleCreateFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id property Added
 
 - 
  list_id_jacek property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  ThreatMatchRuleCreateFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id property Added
 
 - 
  list_id_jacek property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  MachineLearningRuleCreateFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id property Added
 
 - 
  list_id_jacek property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  NewTermsRuleCreateFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id property Added
 
 - 
  list_id_jacek property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  EsqlRuleCreateFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id property Added
 
 - 
  list_id_jacek property Removed
    
 
 - 
  exceptions_list property Modified
    
 
 - 
  EqlRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
  8 structure changes including:
    
    8 Modifications
        Modified
        8
          Breaking
      
      DELETE /api/detection_engine/rules
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  QueryRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
GET /api/detection_engine/rules
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  QueryRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
GET /api/detection_engine/rules/_find
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  data property Modified
    
- EqlRuleResponseFields, QueryRuleResponseFields, SavedQueryRuleResponseFields, ThresholdRuleResponseFields, ThreatMatchRuleResponseFields, MachineLearningRuleResponseFields, NewTermsRuleResponseFields, EsqlRuleResponseFields alternatives Modified
 
 
 - 
  data property Modified
    
 
 - 
  application/json content type Modified
    
 
PATCH /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRulePatchFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id_jacek property Added
 
 - 
  list_id property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  QueryRulePatchFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id_jacek property Added
 
 - 
  list_id property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  SavedQueryRulePatchFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id_jacek property Added
 
 - 
  list_id property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  ThresholdRulePatchFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id_jacek property Added
 
 - 
  list_id property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  ThreatMatchRulePatchFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id_jacek property Added
 
 - 
  list_id property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  MachineLearningRulePatchFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id_jacek property Added
 
 - 
  list_id property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  NewTermsRulePatchFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id_jacek property Added
 
 - 
  list_id property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  EsqlRulePatchProps alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id_jacek property Added
 
 - 
  list_id property Removed
    
 
 - 
  exceptions_list property Modified
    
 
 - 
  EqlRulePatchFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  QueryRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRuleCreateFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id_jacek property Added
 
 - 
  list_id property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  QueryRuleCreateFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id_jacek property Added
 
 - 
  list_id property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  SavedQueryRuleCreateFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id_jacek property Added
 
 - 
  list_id property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  ThresholdRuleCreateFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id_jacek property Added
 
 - 
  list_id property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  ThreatMatchRuleCreateFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id_jacek property Added
 
 - 
  list_id property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  MachineLearningRuleCreateFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id_jacek property Added
 
 - 
  list_id property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  NewTermsRuleCreateFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id_jacek property Added
 
 - 
  list_id property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  EsqlRuleCreateFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id_jacek property Added
 
 - 
  list_id property Removed
    
 
 - 
  exceptions_list property Modified
    
 
 - 
  EqlRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  QueryRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/_bulk_action
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  BulkEditActionResponse alternative Modified
    
- attributes property Modified
 
 
 - 
  BulkEditActionResponse alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/preview
              - Body
 - 
  application/json content type Modified
    
- 
  RulePreviewParams alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id_jacek property Added
 
 - 
  list_id property Removed
    
 - data_view_id, event_category_override, filters, index, tiebreaker_field, timestamp_field properties Added
 
 - 
  exceptions_list property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id_jacek property Added
 
 - 
  list_id property Removed
    
 - 
  language, query properties Modified
    
- Properties are no longer required
 
 - data_view_id, filters, index, saved_id properties Added
 
 - 
  exceptions_list property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id_jacek property Added
 
 - 
  list_id property Removed
    
 - 
  query, language properties Modified
    
- Properties are no longer required
 
 - saved_id, data_view_id, filters, index properties Added
 
 - 
  exceptions_list property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id_jacek property Added
 
 - 
  list_id property Removed
    
 - 
  alert_suppression property Modified
    
- 
  duration property Modified
    
- 
          Property is now required Breaking
 
 - 
          Property is now required 
 - 
  group_by, missing_fields_strategy properties Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  duration property Modified
    
 - 
  language property Modified
    
- Property is no longer required
 
 - threshold, data_view_id, filters, index, saved_id properties Added
 
 - 
  exceptions_list property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id_jacek property Added
 
 - 
  list_id property Removed
    
 - 
  language property Modified
    
- Property is no longer required
 
 - threat_index, threat_mapping, threat_query, concurrent_searches, data_view_id, filters, index, items_per_search, saved_id, threat_filters, threat_indicator_path, threat_language properties Added
 
 - 
  exceptions_list property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id_jacek property Added
 
 - 
  list_id property Removed
    
 - 
  language, query properties Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - anomaly_threshold, array-2 properties Added
 
 - 
  exceptions_list property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id_jacek property Added
 
 - 
  list_id property Removed
    
 - 
  language property Modified
    
- Property is no longer required
 
 - history_window_start, new_terms_fields, data_view_id, filters, index properties Added
 
 - 
  exceptions_list property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id_jacek property Added
 
 - 
  list_id property Removed
    
 
 - 
  exceptions_list property Modified
    
 
 - 
  RulePreviewParams alternative Modified
    
 
PUT /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRuleCreateFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id_jacek property Added
 
 - 
  list_id property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  QueryRuleCreateFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id_jacek property Added
 
 - 
  list_id property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  SavedQueryRuleCreateFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id_jacek property Added
 
 - 
  list_id property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  ThresholdRuleCreateFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id_jacek property Added
 
 - 
  list_id property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  ThreatMatchRuleCreateFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id_jacek property Added
 
 - 
  list_id property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  MachineLearningRuleCreateFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id_jacek property Added
 
 - 
  list_id property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  NewTermsRuleCreateFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id_jacek property Added
 
 - 
  list_id property Removed
    
 
 - 
  exceptions_list property Modified
    
 - 
  EsqlRuleCreateFields alternative Modified
    
- 
  exceptions_list property Modified
    
- 
  list_id property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - list_id_jacek property Added
 
 - 
  list_id property Removed
    
 
 - 
  exceptions_list property Modified
    
 
 - 
  EqlRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  QueryRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- exceptions_list property Modified
 - 
  required_fields_jacek property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
  7 structure changes including:
    
    7 Modifications
        Modified
        7
      
      DELETE /api/detection_engine/rules
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  QueryRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
GET /api/detection_engine/rules
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  QueryRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
GET /api/detection_engine/rules/_find
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  data property Modified
    
- EqlRuleResponseFields, QueryRuleResponseFields, SavedQueryRuleResponseFields, ThresholdRuleResponseFields, ThreatMatchRuleResponseFields, MachineLearningRuleResponseFields, NewTermsRuleResponseFields, EsqlRuleResponseFields alternatives Modified
 
 
 - 
  data property Modified
    
 
 - 
  application/json content type Modified
    
 
PATCH /api/detection_engine/rules
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  QueryRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  QueryRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/_bulk_action
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  BulkEditActionResponse alternative Modified
    
- attributes property Modified
 
 
 - 
  BulkEditActionResponse alternative Modified
    
 
 - 
  application/json content type Modified
    
 
PUT /api/detection_engine/rules
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  QueryRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- required_fields_jacek property Added
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
  8 structure changes including:
    
    8 Modifications
        Modified
        8
          Breaking
      
      DELETE /api/detection_engine/rules
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
GET /api/detection_engine/rules
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
GET /api/detection_engine/rules/_find
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  data property Modified
    
- EqlRuleResponseFields, QueryRuleResponseFields, SavedQueryRuleResponseFields, ThresholdRuleResponseFields, ThreatMatchRuleResponseFields, MachineLearningRuleResponseFields, NewTermsRuleResponseFields, EsqlRuleResponseFields alternatives Modified
 
 
 - 
  data property Modified
    
 
 - 
  application/json content type Modified
    
 
PATCH /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRulePatchFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name-jacek2 property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name property Added
 
 - 
  name-jacek2 property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  QueryRulePatchFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name-jacek2 property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name property Added
 
 - 
  name-jacek2 property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  SavedQueryRulePatchFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name-jacek2 property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name property Added
 
 - 
  name-jacek2 property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  ThresholdRulePatchFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name-jacek2 property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name property Added
 
 - 
  name-jacek2 property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  ThreatMatchRulePatchFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name-jacek2 property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name property Added
 
 - 
  name-jacek2 property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  MachineLearningRulePatchFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name-jacek2 property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name property Added
 
 - 
  name-jacek2 property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  NewTermsRulePatchFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name-jacek2 property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name property Added
 
 - 
  name-jacek2 property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  EsqlRulePatchProps alternative Modified
    
- 
  required_fields property Modified
    
- 
  name-jacek2 property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name property Added
 
 - 
  name-jacek2 property Removed
    
 
 - 
  required_fields property Modified
    
 
 - 
  EqlRulePatchFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRuleCreateFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name-jacek2 property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name property Added
 
 - 
  name-jacek2 property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  QueryRuleCreateFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name-jacek2 property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name property Added
 
 - 
  name-jacek2 property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  SavedQueryRuleCreateFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name-jacek2 property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name property Added
 
 - 
  name-jacek2 property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  ThresholdRuleCreateFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name-jacek2 property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name property Added
 
 - 
  name-jacek2 property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  ThreatMatchRuleCreateFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name-jacek2 property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name property Added
 
 - 
  name-jacek2 property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  MachineLearningRuleCreateFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name-jacek2 property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name property Added
 
 - 
  name-jacek2 property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  NewTermsRuleCreateFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name-jacek2 property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name property Added
 
 - 
  name-jacek2 property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  EsqlRuleCreateFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name-jacek2 property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name property Added
 
 - 
  name-jacek2 property Removed
    
 
 - 
  required_fields property Modified
    
 
 - 
  EqlRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/_bulk_action
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  BulkEditActionResponse alternative Modified
    
- attributes property Modified
 
 
 - 
  BulkEditActionResponse alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/preview
              - Body
 - 
  application/json content type Modified
    
- 
  RulePreviewParams alternative Modified
    
- 
  required_fields property Modified
    
- 
  name-jacek2 property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name property Added
 
 - 
  name-jacek2 property Removed
    
 - data_view_id, event_category_override, filters, index, tiebreaker_field, timestamp_field properties Added
 
 - 
  required_fields property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  required_fields property Modified
    
- 
  name-jacek2 property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name property Added
 
 - 
  name-jacek2 property Removed
    
 - 
  language, query properties Modified
    
- Properties are no longer required
 
 - data_view_id, filters, index, saved_id properties Added
 
 - 
  required_fields property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  required_fields property Modified
    
- 
  name-jacek2 property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name property Added
 
 - 
  name-jacek2 property Removed
    
 - 
  query, language properties Modified
    
- Properties are no longer required
 
 - saved_id, data_view_id, filters, index properties Added
 
 - 
  required_fields property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  required_fields property Modified
    
- 
  name-jacek2 property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name property Added
 
 - 
  name-jacek2 property Removed
    
 - 
  alert_suppression property Modified
    
- 
  duration property Modified
    
- 
          Property is now required Breaking
 
 - 
          Property is now required 
 - 
  group_by, missing_fields_strategy properties Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  duration property Modified
    
 - 
  language property Modified
    
- Property is no longer required
 
 - threshold, data_view_id, filters, index, saved_id properties Added
 
 - 
  required_fields property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  required_fields property Modified
    
- 
  name-jacek2 property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name property Added
 
 - 
  name-jacek2 property Removed
    
 - 
  language property Modified
    
- Property is no longer required
 
 - threat_index, threat_mapping, threat_query, concurrent_searches, data_view_id, filters, index, items_per_search, saved_id, threat_filters, threat_indicator_path, threat_language properties Added
 
 - 
  required_fields property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  required_fields property Modified
    
- 
  name-jacek2 property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name property Added
 
 - 
  name-jacek2 property Removed
    
 - 
  language, query properties Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - anomaly_threshold, array-2 properties Added
 
 - 
  required_fields property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  required_fields property Modified
    
- 
  name-jacek2 property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name property Added
 
 - 
  name-jacek2 property Removed
    
 - 
  language property Modified
    
- Property is no longer required
 
 - history_window_start, new_terms_fields, data_view_id, filters, index properties Added
 
 - 
  required_fields property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  required_fields property Modified
    
- 
  name-jacek2 property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name property Added
 
 - 
  name-jacek2 property Removed
    
 
 - 
  required_fields property Modified
    
 
 - 
  RulePreviewParams alternative Modified
    
 
PUT /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRuleCreateFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name-jacek2 property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name property Added
 
 - 
  name-jacek2 property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  QueryRuleCreateFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name-jacek2 property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name property Added
 
 - 
  name-jacek2 property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  SavedQueryRuleCreateFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name-jacek2 property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name property Added
 
 - 
  name-jacek2 property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  ThresholdRuleCreateFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name-jacek2 property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name property Added
 
 - 
  name-jacek2 property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  ThreatMatchRuleCreateFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name-jacek2 property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name property Added
 
 - 
  name-jacek2 property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  MachineLearningRuleCreateFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name-jacek2 property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name property Added
 
 - 
  name-jacek2 property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  NewTermsRuleCreateFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name-jacek2 property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name property Added
 
 - 
  name-jacek2 property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  EsqlRuleCreateFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name-jacek2 property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name property Added
 
 - 
  name-jacek2 property Removed
    
 
 - 
  required_fields property Modified
    
 
 - 
  EqlRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
  8 structure changes including:
    
    8 Modifications
        Modified
        8
          Breaking
      
      DELETE /api/detection_engine/rules
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
GET /api/detection_engine/rules
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
GET /api/detection_engine/rules/_find
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  data property Modified
    
- EqlRuleResponseFields, QueryRuleResponseFields, SavedQueryRuleResponseFields, ThresholdRuleResponseFields, ThreatMatchRuleResponseFields, MachineLearningRuleResponseFields, NewTermsRuleResponseFields, EsqlRuleResponseFields alternatives Modified
 
 
 - 
  data property Modified
    
 
 - 
  application/json content type Modified
    
 
PATCH /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRulePatchFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name-jacek2 property Added
 
 - 
  name property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  QueryRulePatchFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name-jacek2 property Added
 
 - 
  name property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  SavedQueryRulePatchFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name-jacek2 property Added
 
 - 
  name property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  ThresholdRulePatchFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name-jacek2 property Added
 
 - 
  name property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  ThreatMatchRulePatchFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name-jacek2 property Added
 
 - 
  name property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  MachineLearningRulePatchFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name-jacek2 property Added
 
 - 
  name property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  NewTermsRulePatchFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name-jacek2 property Added
 
 - 
  name property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  EsqlRulePatchProps alternative Modified
    
- 
  required_fields property Modified
    
- 
  name property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name-jacek2 property Added
 
 - 
  name property Removed
    
 
 - 
  required_fields property Modified
    
 
 - 
  EqlRulePatchFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRuleCreateFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name-jacek2 property Added
 
 - 
  name property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  QueryRuleCreateFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name-jacek2 property Added
 
 - 
  name property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  SavedQueryRuleCreateFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name-jacek2 property Added
 
 - 
  name property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  ThresholdRuleCreateFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name-jacek2 property Added
 
 - 
  name property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  ThreatMatchRuleCreateFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name-jacek2 property Added
 
 - 
  name property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  MachineLearningRuleCreateFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name-jacek2 property Added
 
 - 
  name property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  NewTermsRuleCreateFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name-jacek2 property Added
 
 - 
  name property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  EsqlRuleCreateFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name-jacek2 property Added
 
 - 
  name property Removed
    
 
 - 
  required_fields property Modified
    
 
 - 
  EqlRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/_bulk_action
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  BulkEditActionResponse alternative Modified
    
- attributes property Modified
 
 
 - 
  BulkEditActionResponse alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/preview
              - Body
 - 
  application/json content type Modified
    
- 
  RulePreviewParams alternative Modified
    
- 
  required_fields property Modified
    
- 
  name property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name-jacek2 property Added
 
 - 
  name property Removed
    
 - data_view_id, event_category_override, filters, index, tiebreaker_field, timestamp_field properties Added
 
 - 
  required_fields property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  required_fields property Modified
    
- 
  name property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name-jacek2 property Added
 
 - 
  name property Removed
    
 - 
  language, query properties Modified
    
- Properties are no longer required
 
 - data_view_id, filters, index, saved_id properties Added
 
 - 
  required_fields property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  required_fields property Modified
    
- 
  name property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name-jacek2 property Added
 
 - 
  name property Removed
    
 - 
  query, language properties Modified
    
- Properties are no longer required
 
 - saved_id, data_view_id, filters, index properties Added
 
 - 
  required_fields property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  required_fields property Modified
    
- 
  name property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name-jacek2 property Added
 
 - 
  name property Removed
    
 - 
  alert_suppression property Modified
    
- 
  duration property Modified
    
- 
          Property is now required Breaking
 
 - 
          Property is now required 
 - 
  group_by, missing_fields_strategy properties Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  duration property Modified
    
 - 
  language property Modified
    
- Property is no longer required
 
 - threshold, data_view_id, filters, index, saved_id properties Added
 
 - 
  required_fields property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  required_fields property Modified
    
- 
  name property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name-jacek2 property Added
 
 - 
  name property Removed
    
 - 
  language property Modified
    
- Property is no longer required
 
 - threat_index, threat_mapping, threat_query, concurrent_searches, data_view_id, filters, index, items_per_search, saved_id, threat_filters, threat_indicator_path, threat_language properties Added
 
 - 
  required_fields property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  required_fields property Modified
    
- 
  name property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name-jacek2 property Added
 
 - 
  name property Removed
    
 - 
  language, query properties Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - anomaly_threshold, array-2 properties Added
 
 - 
  required_fields property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  required_fields property Modified
    
- 
  name property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name-jacek2 property Added
 
 - 
  name property Removed
    
 - 
  language property Modified
    
- Property is no longer required
 
 - history_window_start, new_terms_fields, data_view_id, filters, index properties Added
 
 - 
  required_fields property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  required_fields property Modified
    
- 
  name property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name-jacek2 property Added
 
 - 
  name property Removed
    
 
 - 
  required_fields property Modified
    
 
 - 
  RulePreviewParams alternative Modified
    
 
PUT /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRuleCreateFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name-jacek2 property Added
 
 - 
  name property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  QueryRuleCreateFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name-jacek2 property Added
 
 - 
  name property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  SavedQueryRuleCreateFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name-jacek2 property Added
 
 - 
  name property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  ThresholdRuleCreateFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name-jacek2 property Added
 
 - 
  name property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  ThreatMatchRuleCreateFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name-jacek2 property Added
 
 - 
  name property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  MachineLearningRuleCreateFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name-jacek2 property Added
 
 - 
  name property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  NewTermsRuleCreateFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name-jacek2 property Added
 
 - 
  name property Removed
    
 
 - 
  required_fields property Modified
    
 - 
  EsqlRuleCreateFields alternative Modified
    
- 
  required_fields property Modified
    
- 
  name property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - name-jacek2 property Added
 
 - 
  name property Removed
    
 
 - 
  required_fields property Modified
    
 
 - 
  EqlRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- required_fields property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
  8 structure changes including:
    
    8 Modifications
        Modified
        8
          Breaking
      
      DELETE /api/detection_engine/rules
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
GET /api/detection_engine/rules
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
GET /api/detection_engine/rules/_find
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  data property Modified
    
- EqlRuleResponseFields, QueryRuleResponseFields, SavedQueryRuleResponseFields, ThresholdRuleResponseFields, ThreatMatchRuleResponseFields, MachineLearningRuleResponseFields, NewTermsRuleResponseFields, EsqlRuleResponseFields alternatives Modified
 
 
 - 
  data property Modified
    
 
 - 
  application/json content type Modified
    
 
PATCH /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  QueryRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  SavedQueryRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  ThresholdRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  ThreatMatchRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  MachineLearningRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  NewTermsRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  EsqlRulePatchProps alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 
 - 
  EqlRulePatchFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  QueryRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  SavedQueryRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  ThresholdRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  ThreatMatchRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  MachineLearningRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  NewTermsRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  EsqlRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 
 - 
  EqlRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/_bulk_action
              - Body
 - 
  application/json content type Modified
    
- 
  BulkEditRules alternative Modified
    
- 
  edit property Modified
    
- BulkActionEditPayloadRuleActions alternative Modified
 
 
 - 
  edit property Modified
    
 
 - 
  BulkEditRules alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  BulkEditActionResponse alternative Modified
    
- attributes property Modified
 
 
 - 
  BulkEditActionResponse alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/preview
              - Body
 - 
  application/json content type Modified
    
- 
  RulePreviewParams alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 - data_view_id, event_category_override, filters, index, tiebreaker_field, timestamp_field properties Added
 
 - 
  actions property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 - 
  language, query properties Modified
    
- Properties are no longer required
 
 - data_view_id, filters, index, saved_id properties Added
 
 - 
  actions property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 - 
  query, language properties Modified
    
- Properties are no longer required
 
 - saved_id, data_view_id, filters, index properties Added
 
 - 
  actions property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 - 
  alert_suppression property Modified
    
- 
  duration property Modified
    
- 
          Property is now required Breaking
 
 - 
          Property is now required 
 - 
  group_by, missing_fields_strategy properties Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  duration property Modified
    
 - 
  language property Modified
    
- Property is no longer required
 
 - threshold, data_view_id, filters, index, saved_id properties Added
 
 - 
  actions property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 - 
  language property Modified
    
- Property is no longer required
 
 - threat_index, threat_mapping, threat_query, concurrent_searches, data_view_id, filters, index, items_per_search, saved_id, threat_filters, threat_indicator_path, threat_language properties Added
 
 - 
  actions property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 - 
  language, query properties Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - anomaly_threshold, array-2 properties Added
 
 - 
  actions property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 - 
  language property Modified
    
- Property is no longer required
 
 - history_window_start, new_terms_fields, data_view_id, filters, index properties Added
 
 - 
  actions property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 
 - 
  RulePreviewParams alternative Modified
    
 
PUT /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  QueryRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  SavedQueryRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  ThresholdRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  ThreatMatchRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  MachineLearningRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  NewTermsRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  EsqlRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 
 - 
  EqlRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
  5 structure changes including:
    
    5 Removals
        Removed
        5
      
      DELETE /api/detection_engine/rules/_bulk_delete
          PATCH /api/detection_engine/rules/_bulk_update
          POST /api/detection_engine/rules/_bulk_create
          POST /api/detection_engine/rules/_bulk_delete
          PUT /api/detection_engine/rules/_bulk_update
          
  13 structure changes including:
    
    13 Modifications
        Modified
        13
          Breaking
      
      DELETE /api/detection_engine/rules
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
DELETE /api/detection_engine/rules/_bulk_delete
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
GET /api/detection_engine/rules
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
GET /api/detection_engine/rules/_find
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  data property Modified
    
- EqlRuleResponseFields, QueryRuleResponseFields, SavedQueryRuleResponseFields, ThresholdRuleResponseFields, ThreatMatchRuleResponseFields, MachineLearningRuleResponseFields, NewTermsRuleResponseFields, EsqlRuleResponseFields alternatives Modified
 
 
 - 
  data property Modified
    
 
 - 
  application/json content type Modified
    
 
PATCH /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRulePatchFields alternative Modified
    
- 
  related_integrations property Modified
    
- 
  jacek_param property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek_param property Removed
    
 
 - 
  related_integrations property Modified
    
 - 
  QueryRulePatchFields alternative Modified
    
- 
  related_integrations property Modified
    
- 
  jacek_param property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek_param property Removed
    
 
 - 
  related_integrations property Modified
    
 - 
  SavedQueryRulePatchFields alternative Modified
    
- 
  related_integrations property Modified
    
- 
  jacek_param property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek_param property Removed
    
 
 - 
  related_integrations property Modified
    
 - 
  ThresholdRulePatchFields alternative Modified
    
- 
  related_integrations property Modified
    
- 
  jacek_param property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek_param property Removed
    
 
 - 
  related_integrations property Modified
    
 - 
  ThreatMatchRulePatchFields alternative Modified
    
- 
  related_integrations property Modified
    
- 
  jacek_param property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek_param property Removed
    
 
 - 
  related_integrations property Modified
    
 - 
  MachineLearningRulePatchFields alternative Modified
    
- 
  related_integrations property Modified
    
- 
  jacek_param property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek_param property Removed
    
 
 - 
  related_integrations property Modified
    
 - 
  NewTermsRulePatchFields alternative Modified
    
- 
  related_integrations property Modified
    
- 
  jacek_param property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek_param property Removed
    
 
 - 
  related_integrations property Modified
    
 - 
  EsqlRulePatchProps alternative Modified
    
- 
  related_integrations property Modified
    
- 
  jacek_param property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek_param property Removed
    
 
 - 
  related_integrations property Modified
    
 
 - 
  EqlRulePatchFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
PATCH /api/detection_engine/rules/_bulk_update
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRulePatchFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Removed
 
 
 - 
  related_integrations property Modified
    
 - 
  QueryRulePatchFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Removed
 
 
 - 
  related_integrations property Modified
    
 - 
  SavedQueryRulePatchFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Removed
 
 
 - 
  related_integrations property Modified
    
 - 
  ThresholdRulePatchFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Removed
 
 
 - 
  related_integrations property Modified
    
 - 
  ThreatMatchRulePatchFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Removed
 
 
 - 
  related_integrations property Modified
    
 - 
  MachineLearningRulePatchFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Removed
 
 
 - 
  related_integrations property Modified
    
 - 
  NewTermsRulePatchFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Removed
 
 
 - 
  related_integrations property Modified
    
 - 
  EsqlRulePatchProps alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Removed
 
 
 - 
  related_integrations property Modified
    
 
 - 
  EqlRulePatchFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- 
  jacek_param property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek_param property Removed
    
 
 - 
  related_integrations property Modified
    
 - 
  QueryRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- 
  jacek_param property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek_param property Removed
    
 
 - 
  related_integrations property Modified
    
 - 
  SavedQueryRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- 
  jacek_param property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek_param property Removed
    
 
 - 
  related_integrations property Modified
    
 - 
  ThresholdRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- 
  jacek_param property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek_param property Removed
    
 
 - 
  related_integrations property Modified
    
 - 
  ThreatMatchRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- 
  jacek_param property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek_param property Removed
    
 
 - 
  related_integrations property Modified
    
 - 
  MachineLearningRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- 
  jacek_param property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek_param property Removed
    
 
 - 
  related_integrations property Modified
    
 - 
  NewTermsRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- 
  jacek_param property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek_param property Removed
    
 
 - 
  related_integrations property Modified
    
 - 
  EsqlRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- 
  jacek_param property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek_param property Removed
    
 
 - 
  related_integrations property Modified
    
 
 - 
  EqlRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/_bulk_action
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  BulkEditActionResponse alternative Modified
    
- attributes property Modified
 
 
 - 
  BulkEditActionResponse alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/_bulk_create
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Removed
 
 
 - 
  related_integrations property Modified
    
 - 
  QueryRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Removed
 
 
 - 
  related_integrations property Modified
    
 - 
  SavedQueryRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Removed
 
 
 - 
  related_integrations property Modified
    
 - 
  ThresholdRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Removed
 
 
 - 
  related_integrations property Modified
    
 - 
  ThreatMatchRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Removed
 
 
 - 
  related_integrations property Modified
    
 - 
  MachineLearningRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Removed
 
 
 - 
  related_integrations property Modified
    
 - 
  NewTermsRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Removed
 
 
 - 
  related_integrations property Modified
    
 - 
  EsqlRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Removed
 
 
 - 
  related_integrations property Modified
    
 
 - 
  EqlRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/_bulk_delete
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/preview
              - Body
 - 
  application/json content type Modified
    
- 
  RulePreviewParams alternative Modified
    
- 
  related_integrations property Modified
    
- 
  jacek_param property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek_param property Removed
    
 - data_view_id, event_category_override, filters, index, tiebreaker_field, timestamp_field properties Added
 
 - 
  related_integrations property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  related_integrations property Modified
    
- 
  jacek_param property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek_param property Removed
    
 - 
  language, query properties Modified
    
- Properties are no longer required
 
 - data_view_id, filters, index, saved_id properties Added
 
 - 
  related_integrations property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  related_integrations property Modified
    
- 
  jacek_param property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek_param property Removed
    
 - 
  query, language properties Modified
    
- Properties are no longer required
 
 - saved_id, data_view_id, filters, index properties Added
 
 - 
  related_integrations property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  related_integrations property Modified
    
- 
  jacek_param property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek_param property Removed
    
 - 
  alert_suppression property Modified
    
- 
  duration property Modified
    
- 
          Property is now required Breaking
 
 - 
          Property is now required 
 - 
  group_by, missing_fields_strategy properties Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  duration property Modified
    
 - 
  language property Modified
    
- Property is no longer required
 
 - threshold, data_view_id, filters, index, saved_id properties Added
 
 - 
  related_integrations property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  related_integrations property Modified
    
- 
  jacek_param property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek_param property Removed
    
 - 
  language property Modified
    
- Property is no longer required
 
 - threat_index, threat_mapping, threat_query, concurrent_searches, data_view_id, filters, index, items_per_search, saved_id, threat_filters, threat_indicator_path, threat_language properties Added
 
 - 
  related_integrations property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  related_integrations property Modified
    
- 
  jacek_param property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek_param property Removed
    
 - 
  language, query properties Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - anomaly_threshold property Added
 - 
  machine_learning_job_id property Added
    
- string-1, array-2 properties Added
 
 
 - 
  related_integrations property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  related_integrations property Modified
    
- 
  jacek_param property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek_param property Removed
    
 - 
  language property Modified
    
- Property is no longer required
 
 - history_window_start, new_terms_fields, data_view_id, filters, index properties Added
 
 - 
  related_integrations property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  related_integrations property Modified
    
- 
  jacek_param property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek_param property Removed
    
 
 - 
  related_integrations property Modified
    
 
 - 
  RulePreviewParams alternative Modified
    
 
PUT /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- 
  jacek_param property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek_param property Removed
    
 
 - 
  related_integrations property Modified
    
 - 
  QueryRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- 
  jacek_param property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek_param property Removed
    
 
 - 
  related_integrations property Modified
    
 - 
  SavedQueryRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- 
  jacek_param property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek_param property Removed
    
 
 - 
  related_integrations property Modified
    
 - 
  ThresholdRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- 
  jacek_param property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek_param property Removed
    
 
 - 
  related_integrations property Modified
    
 - 
  ThreatMatchRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- 
  jacek_param property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek_param property Removed
    
 
 - 
  related_integrations property Modified
    
 - 
  MachineLearningRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- 
  jacek_param property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek_param property Removed
    
 
 - 
  related_integrations property Modified
    
 - 
  NewTermsRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- 
  jacek_param property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek_param property Removed
    
 
 - 
  related_integrations property Modified
    
 - 
  EsqlRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- 
  jacek_param property Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  jacek_param property Removed
    
 
 - 
  related_integrations property Modified
    
 
 - 
  EqlRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
PUT /api/detection_engine/rules/_bulk_update
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Removed
 
 
 - 
  related_integrations property Modified
    
 - 
  QueryRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Removed
 
 
 - 
  related_integrations property Modified
    
 - 
  SavedQueryRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Removed
 
 
 - 
  related_integrations property Modified
    
 - 
  ThresholdRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Removed
 
 
 - 
  related_integrations property Modified
    
 - 
  ThreatMatchRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Removed
 
 
 - 
  related_integrations property Modified
    
 - 
  MachineLearningRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Removed
 
 
 - 
  related_integrations property Modified
    
 - 
  NewTermsRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Removed
 
 
 - 
  related_integrations property Modified
    
 - 
  EsqlRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Removed
 
 
 - 
  related_integrations property Modified
    
 
 - 
  EqlRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
  13 structure changes including:
    
    13 Modifications
        Modified
        13
          Breaking
      
      DELETE /api/detection_engine/rules
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
DELETE /api/detection_engine/rules/_bulk_delete
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
GET /api/detection_engine/rules
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
GET /api/detection_engine/rules/_find
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  data property Modified
    
- EqlRuleResponseFields, QueryRuleResponseFields, SavedQueryRuleResponseFields, ThresholdRuleResponseFields, ThreatMatchRuleResponseFields, MachineLearningRuleResponseFields, NewTermsRuleResponseFields, EsqlRuleResponseFields alternatives Modified
 
 
 - 
  data property Modified
    
 
 - 
  application/json content type Modified
    
 
PATCH /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRulePatchFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  QueryRulePatchFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  SavedQueryRulePatchFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  ThresholdRulePatchFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  ThreatMatchRulePatchFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  MachineLearningRulePatchFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  NewTermsRulePatchFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  EsqlRulePatchProps alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 
 - 
  EqlRulePatchFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
PATCH /api/detection_engine/rules/_bulk_update
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRulePatchFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  QueryRulePatchFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  SavedQueryRulePatchFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  ThresholdRulePatchFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  ThreatMatchRulePatchFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  MachineLearningRulePatchFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  NewTermsRulePatchFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  EsqlRulePatchProps alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 
 - 
  EqlRulePatchFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  QueryRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  SavedQueryRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  ThresholdRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  ThreatMatchRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  MachineLearningRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  NewTermsRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  EsqlRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 
 - 
  EqlRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/_bulk_action
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  BulkEditActionResponse alternative Modified
    
- attributes property Modified
 
 
 - 
  BulkEditActionResponse alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/_bulk_create
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  QueryRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  SavedQueryRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  ThresholdRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  ThreatMatchRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  MachineLearningRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  NewTermsRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  EsqlRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 
 - 
  EqlRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/_bulk_delete
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/preview
              - Body
 - 
  application/json content type Modified
    
- 
  RulePreviewParams alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 - data_view_id, event_category_override, filters, index, tiebreaker_field, timestamp_field properties Added
 
 - 
  related_integrations property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 - 
  language, query properties Modified
    
- Properties are no longer required
 
 - data_view_id, filters, index, saved_id properties Added
 
 - 
  related_integrations property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 - 
  query, language properties Modified
    
- Properties are no longer required
 
 - saved_id, data_view_id, filters, index properties Added
 
 - 
  related_integrations property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 - 
  alert_suppression property Modified
    
- 
  duration property Modified
    
- 
          Property is now required Breaking
 
 - 
          Property is now required 
 - 
  group_by, missing_fields_strategy properties Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  duration property Modified
    
 - 
  language property Modified
    
- Property is no longer required
 
 - threshold, data_view_id, filters, index, saved_id properties Added
 
 - 
  related_integrations property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 - 
  language property Modified
    
- Property is no longer required
 
 - threat_index, threat_mapping, threat_query, concurrent_searches, data_view_id, filters, index, items_per_search, saved_id, threat_filters, threat_indicator_path, threat_language properties Added
 
 - 
  related_integrations property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 - 
  language, query properties Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - anomaly_threshold property Added
 - 
  machine_learning_job_id property Added
    
- string-1, array-2 properties Added
 
 
 - 
  related_integrations property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 - 
  language property Modified
    
- Property is no longer required
 
 - history_window_start, new_terms_fields, data_view_id, filters, index properties Added
 
 - 
  related_integrations property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 
 - 
  RulePreviewParams alternative Modified
    
 
PUT /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  QueryRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  SavedQueryRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  ThresholdRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  ThreatMatchRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  MachineLearningRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  NewTermsRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  EsqlRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 
 - 
  EqlRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
PUT /api/detection_engine/rules/_bulk_update
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  QueryRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  SavedQueryRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  ThresholdRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  ThreatMatchRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  MachineLearningRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  NewTermsRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 - 
  EsqlRuleCreateFields alternative Modified
    
- 
  related_integrations property Modified
    
- jacek_param property Added
 
 
 - 
  related_integrations property Modified
    
 
 - 
  EqlRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- related_integrations property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
  13 structure changes including:
    
    13 Modifications
        Modified
        13
          Breaking
      
      DELETE /api/detection_engine/rules
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  NewTermsRuleResponseFields alternative Modified
    
- 
  history_window_start property Modified
    
- 
          Type is now 
string(nonempty) 
 - 
          Type is now 
 
 - 
  history_window_start property Modified
    
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
DELETE /api/detection_engine/rules/_bulk_delete
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  NewTermsRuleResponseFields alternative Modified
    
- 
  history_window_start property Modified
    
- 
          Type is now 
string(nonempty) 
 - 
          Type is now 
 
 - 
  history_window_start property Modified
    
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
GET /api/detection_engine/rules
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  NewTermsRuleResponseFields alternative Modified
    
- 
  history_window_start property Modified
    
- 
          Type is now 
string(nonempty) 
 - 
          Type is now 
 
 - 
  history_window_start property Modified
    
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
GET /api/detection_engine/rules/_find
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  data property Modified
    
- NewTermsRuleResponseFields alternative Modified
 
 
 - 
  data property Modified
    
 
 - 
  application/json content type Modified
    
 
PATCH /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  NewTermsRulePatchFields alternative Modified
    
- 
  history_window_start property Modified
    
- 
          Type is now 
string(nonempty) 
 - 
          Type is now 
 
 - 
  history_window_start property Modified
    
 
 - 
  NewTermsRulePatchFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  NewTermsRuleResponseFields alternative Modified
    
- 
  history_window_start property Modified
    
- 
          Type is now 
string(nonempty) 
 - 
          Type is now 
 
 - 
  history_window_start property Modified
    
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
PATCH /api/detection_engine/rules/_bulk_update
              - Body
 - 
  application/json content type Modified
    
- 
  NewTermsRulePatchFields alternative Modified
    
- 
  history_window_start property Modified
    
- 
          Type is now 
string(nonempty) 
 - 
          Type is now 
 
 - 
  history_window_start property Modified
    
 
 - 
  NewTermsRulePatchFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  NewTermsRuleResponseFields alternative Modified
    
- 
  history_window_start property Modified
    
- 
          Type is now 
string(nonempty) 
 - 
          Type is now 
 
 - 
  history_window_start property Modified
    
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  NewTermsRuleCreateFields alternative Modified
    
- 
  history_window_start property Modified
    
- 
          Type is now 
string(nonempty) 
 - 
          Type is now 
 
 - 
  history_window_start property Modified
    
 
 - 
  NewTermsRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  NewTermsRuleResponseFields alternative Modified
    
- 
  history_window_start property Modified
    
- 
          Type is now 
string(nonempty) 
 - 
          Type is now 
 
 - 
  history_window_start property Modified
    
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/_bulk_action
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  BulkEditActionResponse alternative Modified
    
- attributes property Modified
 
 
 - 
  BulkEditActionResponse alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/_bulk_create
              - Body
 - 
  application/json content type Modified
    
- 
  NewTermsRuleCreateFields alternative Modified
    
- 
  history_window_start property Modified
    
- 
          Type is now 
string(nonempty) 
 - 
          Type is now 
 
 - 
  history_window_start property Modified
    
 
 - 
  NewTermsRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  NewTermsRuleResponseFields alternative Modified
    
- 
  history_window_start property Modified
    
- 
          Type is now 
string(nonempty) 
 - 
          Type is now 
 
 - 
  history_window_start property Modified
    
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/_bulk_delete
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  NewTermsRuleResponseFields alternative Modified
    
- 
  history_window_start property Modified
    
- 
          Type is now 
string(nonempty) 
 - 
          Type is now 
 
 - 
  history_window_start property Modified
    
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/preview
              - Body
 - 
  application/json content type Modified
    
- 
  RulePreviewParams alternative Modified
    
- data_view_id, event_category_override, filters, index, tiebreaker_field, timestamp_field properties Added
 
 - 
  RulePreviewParams alternative Modified
    
- 
  language, query properties Modified
    
- Properties are no longer required
 
 - data_view_id, filters, index, saved_id properties Added
 
 - 
  language, query properties Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  query, language properties Modified
    
- Properties are no longer required
 
 - saved_id, data_view_id, filters, index properties Added
 
 - 
  query, language properties Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  alert_suppression property Modified
    
- 
  duration property Modified
    
- 
          Property is now required Breaking
 
 - 
          Property is now required 
 - 
  group_by, missing_fields_strategy properties Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  duration property Modified
    
 - 
  language property Modified
    
- Property is no longer required
 
 - threshold, data_view_id, filters, index, saved_id properties Added
 
 - 
  alert_suppression property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  language property Modified
    
- Property is no longer required
 
 - threat_index, threat_mapping, threat_query, concurrent_searches, data_view_id, filters, index, items_per_search, saved_id, threat_filters, threat_indicator_path, threat_language properties Added
 
 - 
  language property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  language, query properties Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - anomaly_threshold property Added
 - 
  machine_learning_job_id property Added
    
- string-1, array-2 properties Added
 
 
 - 
  language, query properties Removed
    
 - 
  RulePreviewParams alternative Modified
    
- 
  language property Modified
    
- Property is no longer required
 
 - history_window_start, new_terms_fields, data_view_id, filters, index properties Added
 
 - 
  language property Modified
    
 
 - 
  RulePreviewParams alternative Modified
    
 
PUT /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  NewTermsRuleCreateFields alternative Modified
    
- 
  history_window_start property Modified
    
- 
          Type is now 
string(nonempty) 
 - 
          Type is now 
 
 - 
  history_window_start property Modified
    
 
 - 
  NewTermsRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  NewTermsRuleResponseFields alternative Modified
    
- 
  history_window_start property Modified
    
- 
          Type is now 
string(nonempty) 
 - 
          Type is now 
 
 - 
  history_window_start property Modified
    
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
PUT /api/detection_engine/rules/_bulk_update
              - Body
 - 
  application/json content type Modified
    
- 
  NewTermsRuleCreateFields alternative Modified
    
- 
  history_window_start property Modified
    
- 
          Type is now 
string(nonempty) 
 - 
          Type is now 
 
 - 
  history_window_start property Modified
    
 
 - 
  NewTermsRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  NewTermsRuleResponseFields alternative Modified
    
- 
  history_window_start property Modified
    
- 
          Type is now 
string(nonempty) 
 - 
          Type is now 
 
 - 
  history_window_start property Modified
    
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
  13 structure changes including:
    
    13 Modifications
        Modified
        13
          Breaking
      
      DELETE /api/detection_engine/rules
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  NewTermsRuleResponseFields alternative Modified
    
- 
  HistoryWindowStart property Modified
    
- 
          Type is no longer 
string(nonempty)Breaking 
 - 
          Type is no longer 
 
 - 
  HistoryWindowStart property Modified
    
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
DELETE /api/detection_engine/rules/_bulk_delete
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  NewTermsRuleResponseFields alternative Modified
    
- 
  HistoryWindowStart property Modified
    
- 
          Type is no longer 
string(nonempty) 
 - 
          Type is no longer 
 
 - 
  HistoryWindowStart property Modified
    
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
GET /api/detection_engine/rules
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  NewTermsRuleResponseFields alternative Modified
    
- 
  HistoryWindowStart property Modified
    
- 
          Type is no longer 
string(nonempty)Breaking 
 - 
          Type is no longer 
 
 - 
  HistoryWindowStart property Modified
    
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
GET /api/detection_engine/rules/_find
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  data property Modified
    
- NewTermsRuleResponseFields alternative Modified
 
 
 - 
  data property Modified
    
 
 - 
  application/json content type Modified
    
 
PATCH /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  NewTermsRulePatchFields alternative Modified
    
- 
  HistoryWindowStart property Modified
    
- 
          Type is no longer 
string(nonempty)Breaking 
 - 
          Type is no longer 
 
 - 
  HistoryWindowStart property Modified
    
 
 - 
  NewTermsRulePatchFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  NewTermsRuleResponseFields alternative Modified
    
- 
  HistoryWindowStart property Modified
    
- 
          Type is no longer 
string(nonempty)Breaking 
 - 
          Type is no longer 
 
 - 
  HistoryWindowStart property Modified
    
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
PATCH /api/detection_engine/rules/_bulk_update
              - Body
 - 
  application/json content type Modified
    
- 
  NewTermsRulePatchFields alternative Modified
    
- 
  HistoryWindowStart property Modified
    
- 
          Type is no longer 
string(nonempty) 
 - 
          Type is no longer 
 
 - 
  HistoryWindowStart property Modified
    
 
 - 
  NewTermsRulePatchFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  NewTermsRuleResponseFields alternative Modified
    
- 
  HistoryWindowStart property Modified
    
- 
          Type is no longer 
string(nonempty) 
 - 
          Type is no longer 
 
 - 
  HistoryWindowStart property Modified
    
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  NewTermsRuleCreateFields alternative Modified
    
- 
  HistoryWindowStart property Modified
    
- 
          Type is no longer 
string(nonempty)Breaking 
 - 
          Type is no longer 
 
 - 
  HistoryWindowStart property Modified
    
 
 - 
  NewTermsRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  NewTermsRuleResponseFields alternative Modified
    
- 
  HistoryWindowStart property Modified
    
- 
          Type is no longer 
string(nonempty)Breaking 
 - 
          Type is no longer 
 
 - 
  HistoryWindowStart property Modified
    
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/_bulk_action
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  BulkEditActionResponse alternative Modified
    
- attributes property Modified
 
 
 - 
  BulkEditActionResponse alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/_bulk_create
              - Body
 - 
  application/json content type Modified
    
- 
  NewTermsRuleCreateFields alternative Modified
    
- 
  HistoryWindowStart property Modified
    
- 
          Type is no longer 
string(nonempty) 
 - 
          Type is no longer 
 
 - 
  HistoryWindowStart property Modified
    
 
 - 
  NewTermsRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  NewTermsRuleResponseFields alternative Modified
    
- 
  HistoryWindowStart property Modified
    
- 
          Type is no longer 
string(nonempty) 
 - 
          Type is no longer 
 
 - 
  HistoryWindowStart property Modified
    
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/_bulk_delete
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  NewTermsRuleResponseFields alternative Modified
    
- 
  HistoryWindowStart property Modified
    
- 
          Type is no longer 
string(nonempty) 
 - 
          Type is no longer 
 
 - 
  HistoryWindowStart property Modified
    
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/preview
              - Body
 - 
  application/json content type Modified
    
- 
  RulePreviewParams alternative Modified
    
- data_view_id, event_category_override, filters, index, tiebreaker_field, timestamp_field properties Added
 
 - 
  RulePreviewParams alternative Modified
    
- 
  language, query properties Modified
    
- Properties are no longer required
 
 - data_view_id, filters, index, saved_id properties Added
 
 - 
  language, query properties Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  query, language properties Modified
    
- Properties are no longer required
 
 - saved_id, data_view_id, filters, index properties Added
 
 - 
  query, language properties Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  alert_suppression property Modified
    
- 
  duration property Modified
    
- 
          Property is now required Breaking
 
 - 
          Property is now required 
 - 
  group_by, missing_fields_strategy properties Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  duration property Modified
    
 - 
  language property Modified
    
- Property is no longer required
 
 - threshold, data_view_id, filters, index, saved_id properties Added
 
 - 
  alert_suppression property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  language property Modified
    
- Property is no longer required
 
 - threat_index, threat_mapping, threat_query, concurrent_searches, data_view_id, filters, index, items_per_search, saved_id, threat_filters, threat_indicator_path, threat_language properties Added
 
 - 
  language property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  language, query properties Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - anomaly_threshold property Added
 - 
  machine_learning_job_id property Added
    
- string-1, array-2 properties Added
 
 
 - 
  language, query properties Removed
    
 - 
  RulePreviewParams alternative Modified
    
- 
  language property Modified
    
- Property is no longer required
 
 - HistoryWindowStart, new_terms_fields, data_view_id, filters, index properties Added
 
 - 
  language property Modified
    
 
 - 
  RulePreviewParams alternative Modified
    
 
PUT /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  NewTermsRuleCreateFields alternative Modified
    
- 
  HistoryWindowStart property Modified
    
- 
          Type is no longer 
string(nonempty)Breaking 
 - 
          Type is no longer 
 
 - 
  HistoryWindowStart property Modified
    
 
 - 
  NewTermsRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  NewTermsRuleResponseFields alternative Modified
    
- 
  HistoryWindowStart property Modified
    
- 
          Type is no longer 
string(nonempty)Breaking 
 - 
          Type is no longer 
 
 - 
  HistoryWindowStart property Modified
    
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
PUT /api/detection_engine/rules/_bulk_update
              - Body
 - 
  application/json content type Modified
    
- 
  NewTermsRuleCreateFields alternative Modified
    
- 
  HistoryWindowStart property Modified
    
- 
          Type is no longer 
string(nonempty) 
 - 
          Type is no longer 
 
 - 
  HistoryWindowStart property Modified
    
 
 - 
  NewTermsRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  NewTermsRuleResponseFields alternative Modified
    
- 
  HistoryWindowStart property Modified
    
- 
          Type is no longer 
string(nonempty) 
 - 
          Type is no longer 
 
 - 
  HistoryWindowStart property Modified
    
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
  5 structure changes including:
    
    5 Additions
        Added
        5
      
      DELETE /api/detection_engine/rules/_bulk_delete
          PATCH /api/detection_engine/rules/_bulk_update
          POST /api/detection_engine/rules/_bulk_create
          POST /api/detection_engine/rules/_bulk_delete
          PUT /api/detection_engine/rules/_bulk_update
          
  5 structure changes including:
    
    5 Removals
        Removed
        5
      
      DELETE /api/detection_engine/rules/_bulk_delete
          PATCH /api/detection_engine/rules/_bulk_update
          POST /api/detection_engine/rules/_bulk_create
          POST /api/detection_engine/rules/_bulk_delete
          PUT /api/detection_engine/rules/_bulk_update
          
  1 structure change including:
    
    1 Modification
        Modified
        1
      
      POST /api/detection_engine/rules/_bulk_create
              - Operation is no longer In v9.0.0, this API will be deprecated. Use the 
POST /api/detection_engine/rules/_createAPI instead. 
  1 structure change including:
    
    1 Modification
        Modified
        1
      
      POST /api/detection_engine/rules/_bulk_create
              - Operation is now In v9.0.0, this API will be deprecated. Use the 
POST /api/detection_engine/rules/_createAPI instead. - Operation is no longer In v9.0.0, this API will be deprecated. Use the 
POST /api/detection_engine/rules/_createAPI instead. 
  2 structure changes including:
    
    2 Modifications
        Modified
        2
      
      POST /api/detection_engine/rules
              - Operation is no longer Jacek In v9.0.0, this API will be deprecated. Use the 
POST /api/detection_engine/rules/_createAPI instead. 
POST /api/detection_engine/rules/_bulk_create
              - Operation is now In v9.0.0, this API will be deprecated. Use the 
POST /api/detection_engine/rules/_createAPI instead. 
  1 structure change including:
    
    1 Modification
        Modified
        1
      
      POST /api/detection_engine/rules
              - Operation is now Jacek In v9.0.0, this API will be deprecated. Use the 
POST /api/detection_engine/rules/_createAPI instead. 
  13 structure changes including:
    
    13 Modifications
        Modified
        13
          Breaking
      
      DELETE /api/detection_engine/rules
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
DELETE /api/detection_engine/rules/_bulk_delete
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
GET /api/detection_engine/rules
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
GET /api/detection_engine/rules/_find
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  data property Modified
    
- EqlRuleResponseFields, QueryRuleResponseFields, SavedQueryRuleResponseFields, ThresholdRuleResponseFields, ThreatMatchRuleResponseFields, MachineLearningRuleResponseFields, NewTermsRuleResponseFields, EsqlRuleResponseFields alternatives Modified
 
 
 - 
  data property Modified
    
 
 - 
  application/json content type Modified
    
 
PATCH /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  QueryRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  SavedQueryRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  ThresholdRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  ThreatMatchRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  MachineLearningRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  NewTermsRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  EsqlRulePatchProps alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 
 - 
  EqlRulePatchFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
PATCH /api/detection_engine/rules/_bulk_update
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  QueryRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  SavedQueryRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  ThresholdRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  ThreatMatchRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  MachineLearningRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  NewTermsRulePatchFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  EsqlRulePatchProps alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 
 - 
  EqlRulePatchFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  QueryRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  SavedQueryRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  ThresholdRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  ThreatMatchRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  MachineLearningRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  NewTermsRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  EsqlRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 
 - 
  EqlRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/_bulk_action
              - Body
 - 
  application/json content type Modified
    
- 
  BulkEditRules alternative Modified
    
- 
  edit property Modified
    
- BulkActionEditPayloadRuleActions alternative Modified
 
 
 - 
  edit property Modified
    
 
 - 
  BulkEditRules alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  BulkEditActionResponse alternative Modified
    
- attributes property Modified
 
 
 - 
  BulkEditActionResponse alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/_bulk_create
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  QueryRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  SavedQueryRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  ThresholdRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  ThreatMatchRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  MachineLearningRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  NewTermsRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  EsqlRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 
 - 
  EqlRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/_bulk_delete
              - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
POST /api/detection_engine/rules/preview
              - Body
 - 
  application/json content type Modified
    
- 
  RulePreviewParams alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 - data_view_id, event_category_override, filters, index, tiebreaker_field, timestamp_field properties Added
 
 - 
  actions property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 - 
  language, query properties Modified
    
- Properties are no longer required
 
 - data_view_id, filters, index, saved_id properties Added
 
 - 
  actions property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 - 
  query, language properties Modified
    
- Properties are no longer required
 
 - saved_id, data_view_id, filters, index properties Added
 
 - 
  actions property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 - 
  alert_suppression property Modified
    
- 
  duration property Modified
    
- 
          Property is now required Breaking
 
 - 
          Property is now required 
 - 
  group_by, missing_fields_strategy properties Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 
 - 
  duration property Modified
    
 - 
  language property Modified
    
- Property is no longer required
 
 - threshold, data_view_id, filters, index, saved_id properties Added
 
 - 
  actions property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 - 
  language property Modified
    
- Property is no longer required
 
 - threat_index, threat_mapping, threat_query, concurrent_searches, data_view_id, filters, index, items_per_search, saved_id, threat_filters, threat_indicator_path, threat_language properties Added
 
 - 
  actions property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 - 
  language, query properties Removed
    
- 
          Removing a resource is always breaking unless it was deprecated before Breaking
 
 - 
          Removing a resource is always breaking unless it was deprecated before 
 - anomaly_threshold property Added
 - 
  machine_learning_job_id property Added
    
- string-1, array-2 properties Added
 
 
 - 
  actions property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 - 
  language property Modified
    
- Property is no longer required
 
 - history_window_start, new_terms_fields, data_view_id, filters, index properties Added
 
 - 
  actions property Modified
    
 - 
  RulePreviewParams alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 
 - 
  RulePreviewParams alternative Modified
    
 
PUT /api/detection_engine/rules
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  QueryRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  SavedQueryRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  ThresholdRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  ThreatMatchRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  MachineLearningRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  NewTermsRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  EsqlRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 
 - 
  EqlRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified
    
 
PUT /api/detection_engine/rules/_bulk_update
              - Body
 - 
  application/json content type Modified
    
- 
  EqlRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  QueryRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  SavedQueryRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  ThresholdRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  ThreatMatchRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  MachineLearningRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  NewTermsRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 - 
  EsqlRuleCreateFields alternative Modified
    
- 
  actions property Modified
    
- alerts_filter property Modified
 
 
 - 
  actions property Modified
    
 
 - 
  EqlRuleCreateFields alternative Modified
    
 - Response
 - 
  200 response Modified
    
- 
  application/json content type Modified
    
- 
  EqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  QueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  SavedQueryRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThresholdRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  ThreatMatchRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  MachineLearningRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  NewTermsRuleResponseFields alternative Modified
    
- actions property Modified
 
 - 
  EsqlRuleResponseFields alternative Modified
    
- actions property Modified
 
 
 - 
  EqlRuleResponseFields alternative Modified
    
 
 - 
  application/json content type Modified