﻿---
title: stack kb security-detections-api import-rules cli command
description: Import detection rules Behaviour flags: --dry-run — validate all inputs and exit without performing any action 
url: https://www.elastic.co/elastic/docs-builder/docs/4118/reference/elastic-cli/cli/stack/kb/security-detections-api/import-rules
applies_to:
  - Elastic Cloud Serverless: Preview
  - Elastic Stack: Preview
---

# stack kb security-detections-api import-rules cli command
<cli-modifiers>
</cli-modifiers>

```bash
elastic stack kb security-detections-api import-rules [options]
```

Import detection rules
**Behaviour flags:**
`--dry-run` — validate all inputs and exit without performing any action

## Options

<definitions>
  <definition term="--overwrite">
    Determines whether existing rules with the same `rule_id` are overwritten.
  </definition>
  <definition term="--overwrite-exceptions">
    Determines whether existing exception lists with the same `list_id` are overwritten. Both the exception list container and its items are overwritten.
  </definition>
  <definition term="--overwrite-action-connectors">
    Determines whether existing actions with the same `kibana.alert.rule.actions.id` are overwritten.
  </definition>
  <definition term="--as-new-list">
    Generates a new list ID for each imported exception list.
  </definition>
  <definition term="--file string">
    The `.ndjson` file containing the rules.
  </definition>
  <definition term="--input-file string">
    path to a JSON file to use as command input
  </definition>
  <definition term="--dry-run">
    validate all inputs and exit without performing any action (preview changes without applying them)
  </definition>
</definitions>


## Global Options

<definitions>
  <definition term="--json">
    output as JSON
  </definition>
</definitions>