API structure has changed
4 structure changes including:
4 Modifications
Modified
4
Breaking
PATCH /api/detection_engine/rules
- Body
-
application/json content type Modified
-
EqlRulePatchFields alternative Modified
-
version property Removed
-
Removing a resource is always breaking unless it was deprecated before Breaking
-
Removing a resource is always breaking unless it was deprecated before
-
version property Removed
-
QueryRulePatchFields alternative Modified
-
version property Removed
-
Removing a resource is always breaking unless it was deprecated before Breaking
-
Removing a resource is always breaking unless it was deprecated before
-
version property Removed
-
SavedQueryRulePatchFields alternative Modified
-
version property Removed
-
Removing a resource is always breaking unless it was deprecated before Breaking
-
Removing a resource is always breaking unless it was deprecated before
-
version property Removed
-
ThresholdRulePatchFields alternative Modified
-
version property Removed
-
Removing a resource is always breaking unless it was deprecated before Breaking
-
Removing a resource is always breaking unless it was deprecated before
-
version property Removed
-
ThreatMatchRulePatchFields alternative Modified
-
version property Removed
-
Removing a resource is always breaking unless it was deprecated before Breaking
-
Removing a resource is always breaking unless it was deprecated before
-
version property Removed
-
MachineLearningRulePatchFields alternative Modified
-
version property Removed
-
Removing a resource is always breaking unless it was deprecated before Breaking
-
Removing a resource is always breaking unless it was deprecated before
-
version property Removed
-
NewTermsRulePatchFields alternative Modified
-
version property Removed
-
Removing a resource is always breaking unless it was deprecated before Breaking
-
Removing a resource is always breaking unless it was deprecated before
-
version property Removed
-
EsqlRulePatchProps alternative Modified
-
version property Removed
-
Removing a resource is always breaking unless it was deprecated before Breaking
-
Removing a resource is always breaking unless it was deprecated before
-
version property Removed
-
EqlRulePatchFields alternative Modified
POST /api/detection_engine/rules
- Body
-
application/json content type Modified
-
EqlRuleCreateFields alternative Modified
-
version property Removed
-
Removing a resource is always breaking unless it was deprecated before Breaking
-
Removing a resource is always breaking unless it was deprecated before
-
version property Removed
-
QueryRuleCreateFields alternative Modified
-
version property Removed
-
Removing a resource is always breaking unless it was deprecated before Breaking
-
Removing a resource is always breaking unless it was deprecated before
-
version property Removed
-
SavedQueryRuleCreateFields alternative Modified
-
version property Removed
-
Removing a resource is always breaking unless it was deprecated before Breaking
-
Removing a resource is always breaking unless it was deprecated before
-
version property Removed
-
ThresholdRuleCreateFields alternative Modified
-
version property Removed
-
Removing a resource is always breaking unless it was deprecated before Breaking
-
Removing a resource is always breaking unless it was deprecated before
-
version property Removed
-
ThreatMatchRuleCreateFields alternative Modified
-
version property Removed
-
Removing a resource is always breaking unless it was deprecated before Breaking
-
Removing a resource is always breaking unless it was deprecated before
-
version property Removed
-
MachineLearningRuleCreateFields alternative Modified
-
version property Removed
-
Removing a resource is always breaking unless it was deprecated before Breaking
-
Removing a resource is always breaking unless it was deprecated before
-
version property Removed
-
NewTermsRuleCreateFields alternative Modified
-
version property Removed
-
Removing a resource is always breaking unless it was deprecated before Breaking
-
Removing a resource is always breaking unless it was deprecated before
-
version property Removed
-
EsqlRuleCreateFields alternative Modified
-
version property Removed
-
Removing a resource is always breaking unless it was deprecated before Breaking
-
Removing a resource is always breaking unless it was deprecated before
-
version property Removed
-
EqlRuleCreateFields alternative Modified
POST /api/detection_engine/rules/preview
- Body
-
application/json content type Modified
-
RulePreviewParams alternative Modified
-
version property Removed
-
Removing a resource is always breaking unless it was deprecated before Breaking
-
Removing a resource is always breaking unless it was deprecated before
- data_view_id, event_category_override, filters, index, tiebreaker_field, timestamp_field properties Added
-
version property Removed
-
RulePreviewParams alternative Modified
-
language, query properties Modified
- Properties are no longer required
-
version property Removed
-
Removing a resource is always breaking unless it was deprecated before Breaking
-
Removing a resource is always breaking unless it was deprecated before
- data_view_id, filters, index, saved_id properties Added
-
language, query properties Modified
-
RulePreviewParams alternative Modified
-
query, language properties Modified
- Properties are no longer required
-
version property Removed
-
Removing a resource is always breaking unless it was deprecated before Breaking
-
Removing a resource is always breaking unless it was deprecated before
- saved_id, data_view_id, filters, index properties Added
-
query, language properties Modified
-
RulePreviewParams alternative Modified
-
alert_suppression property Modified
-
duration property Modified
-
Property is now required Breaking
-
Property is now required
-
group_by, missing_fields_strategy properties Removed
-
Removing a resource is always breaking unless it was deprecated before Breaking
-
Removing a resource is always breaking unless it was deprecated before
-
duration property Modified
-
language property Modified
- Property is no longer required
-
version property Removed
-
Removing a resource is always breaking unless it was deprecated before Breaking
-
Removing a resource is always breaking unless it was deprecated before
- threshold, data_view_id, filters, index, saved_id properties Added
-
alert_suppression property Modified
-
RulePreviewParams alternative Modified
-
language property Modified
- Property is no longer required
-
version property Removed
-
Removing a resource is always breaking unless it was deprecated before Breaking
-
Removing a resource is always breaking unless it was deprecated before
- threat_index, threat_mapping, threat_query, concurrent_searches, data_view_id, filters, index, items_per_search, saved_id, threat_filters, threat_indicator_path, threat_language properties Added
-
language property Modified
-
RulePreviewParams alternative Modified
-
version, language, query properties Removed
-
Removing a resource is always breaking unless it was deprecated before Breaking
-
Removing a resource is always breaking unless it was deprecated before
- anomaly_threshold, array-2 properties Added
-
version, language, query properties Removed
-
RulePreviewParams alternative Modified
-
language property Modified
- Property is no longer required
-
version property Removed
-
Removing a resource is always breaking unless it was deprecated before Breaking
-
Removing a resource is always breaking unless it was deprecated before
- history_window_start, new_terms_fields, data_view_id, filters, index properties Added
-
language property Modified
-
RulePreviewParams alternative Modified
-
version property Removed
-
Removing a resource is always breaking unless it was deprecated before Breaking
-
Removing a resource is always breaking unless it was deprecated before
-
version property Removed
-
RulePreviewParams alternative Modified
PUT /api/detection_engine/rules
- Body
-
application/json content type Modified
-
EqlRuleCreateFields alternative Modified
-
version property Removed
-
Removing a resource is always breaking unless it was deprecated before Breaking
-
Removing a resource is always breaking unless it was deprecated before
-
version property Removed
-
QueryRuleCreateFields alternative Modified
-
version property Removed
-
Removing a resource is always breaking unless it was deprecated before Breaking
-
Removing a resource is always breaking unless it was deprecated before
-
version property Removed
-
SavedQueryRuleCreateFields alternative Modified
-
version property Removed
-
Removing a resource is always breaking unless it was deprecated before Breaking
-
Removing a resource is always breaking unless it was deprecated before
-
version property Removed
-
ThresholdRuleCreateFields alternative Modified
-
version property Removed
-
Removing a resource is always breaking unless it was deprecated before Breaking
-
Removing a resource is always breaking unless it was deprecated before
-
version property Removed
-
ThreatMatchRuleCreateFields alternative Modified
-
version property Removed
-
Removing a resource is always breaking unless it was deprecated before Breaking
-
Removing a resource is always breaking unless it was deprecated before
-
version property Removed
-
MachineLearningRuleCreateFields alternative Modified
-
version property Removed
-
Removing a resource is always breaking unless it was deprecated before Breaking
-
Removing a resource is always breaking unless it was deprecated before
-
version property Removed
-
NewTermsRuleCreateFields alternative Modified
-
version property Removed
-
Removing a resource is always breaking unless it was deprecated before Breaking
-
Removing a resource is always breaking unless it was deprecated before
-
version property Removed
-
EsqlRuleCreateFields alternative Modified
-
version property Removed
-
Removing a resource is always breaking unless it was deprecated before Breaking
-
Removing a resource is always breaking unless it was deprecated before
-
version property Removed
-
EqlRuleCreateFields alternative Modified