Apply a bulk action to detection rules

POST /api/detection_engine/rules/_bulk_action

Apply a bulk action, such as bulk edit, duplicate, or delete, to multiple detection rules. The bulk action is applied to all rules that match the query or to the rules listed by their IDs.

Query parameters

  • dry_run boolean

    Enables dry run mode for the request call.

application/json; Elastic-Api-Version=2023-10-31

Body object

One of:

Responses

  • 200 application/json; Elastic-Api-Version=2023-10-31

    OK

    One of: