stack kb security-detections-api rule-preview cli command
elastic stack kb security-detections-api rule-preview \
--description <description> \
--name <name> \
--risk-score <risk-score> \
--severity <severity> \
--type <type> \
--invocation-count <invocation-count> \
--timeframe-end <timeframe-end> \
[options]
Preview rule alerts generated on specified time range
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--descriptionstringrequired--namestringrequired--risk-scorenumberrequired--severityenumrequired-
Values: low, medium, high, critical
--typeenumrequired-
Rule type
Values: esql
--invocation-countnumberrequired--timeframe-endstringrequired--enable-logged-requests- Enables logging and returning in response ES queries, performed during rule execution
--actionsstring[]-
Array defining the automated actions (notifications) taken when alerts are generated.
Repeatable: pass
--actionsmultiple times to supply more than one value --alias-purposeenum-
Values: savedObjectConversion, savedObjectImport
--alias-target-idstring-
Repeatable: pass
--authormultiple times to supply more than one value --building-block-typestring--enabled--exceptions-liststring[]-
Repeatable: pass
--exceptions-listmultiple times to supply more than one value --false-positivesstring[]-
Repeatable: pass
--false-positivesmultiple times to supply more than one value --fromstring--intervalstring--investigation-fieldsstring--licensestring--max-signalsnumber--metastring--namespacestring--notestring--outcomeenum-
Values: exactMatch, aliasMatch, conflict
--output-indexstring--referencesstring[]-
Repeatable: pass
--referencesmultiple times to supply more than one value -
Repeatable: pass
--related-integrationsmultiple times to supply more than one value --required-fieldsstring[]-
Elasticsearch fields and their types that need to be present for the rule to function.
info The value of
required_fieldsdoes not affect the rule’s behavior, and specifying it incorrectly won’t cause the rule to fail. Userequired_fieldsas an informational property to document the fields that the rule expects to be present in the data.Repeatable: pass
--required-fieldsmultiple times to supply more than one value --response-actionsstring[]-
Repeatable: pass
--response-actionsmultiple times to supply more than one value --risk-score-mappingstring[]-
Repeatable: pass
--risk-score-mappingmultiple times to supply more than one value --rule-idstring--rule-name-overridestring--setupstring--severity-mappingstring[]-
Repeatable: pass
--severity-mappingmultiple times to supply more than one value -
Repeatable: pass
--tagsmultiple times to supply more than one value --threatstring[]-
Repeatable: pass
--threatmultiple times to supply more than one value --throttlestring--timeline-idstring--timeline-titlestring--timestamp-overridestring--timestamp-override-fallback-disabled--tostring--versionnumber--languageenum-
Values: esql
--querystring--alert-suppressionstring--data-view-idstring--event-category-overridestring--filtersstring[]-
Repeatable: pass
--filtersmultiple times to supply more than one value --indexstring[]-
Repeatable: pass
--indexmultiple times to supply more than one value --tiebreaker-fieldstring--timestamp-fieldstring--saved-idstring--thresholdstring--threat-indexstring[]-
Repeatable: pass
--threat-indexmultiple times to supply more than one value --threat-mappingstring[]-
Repeatable: pass
--threat-mappingmultiple times to supply more than one value --threat-querystring--concurrent-searchesnumber--items-per-searchnumber--threat-filtersstring[]-
Repeatable: pass
--threat-filtersmultiple times to supply more than one value --threat-indicator-pathstring--threat-languageenum-
Values: kuery, lucene
--anomaly-thresholdnumber--machine-learning-job-idstring-
Repeatable: pass
--machine-learning-job-idmultiple times to supply more than one value --history-window-startstring--new-terms-fieldsstring[]-
Repeatable: pass
--new-terms-fieldsmultiple times to supply more than one value --input-filestring- path to a JSON file to use as command input
--dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--json-
output as JSON