stack kb security-detections-api find-rules cli command
Auth required
Idempotent
Scope: global
elastic stack kb security-detections-api find-rules [options]
List all detection rules
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--fieldsstring--filterstring- Search query
--sort-fieldstring- Field to sort by
--sort-orderstring- Sort order
--pagenumber- Page number
--per-pagenumber- Rules per page
--gaps-range-startstring- Gaps range start
--gaps-range-endstring- Gaps range end
--gap-fill-statusesstring- Gap fill statuses
--gap-auto-fill-scheduler-idstring- Gap auto fill scheduler ID used to determine gap fill status for rules
--input-filestring- path to a JSON file to use as command input
--[no-]dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--[no-]json-
output as JSON