Clone Rule Public Api

Clone a rule into a new rule in your organization.

The source rule must exist in your session organization; a rule owned by another
tenant returns 404. The new rule is returned in full, exactly as
GET /rules/{rule_id} would return it, with a fresh rule_id at version 1.

Supported rule types: atomic_sql and scheduled_sql. Other types return 400.

What is copied: content, severity, tags, detection_categories,
data_sources and rule_details come from the source rule. title defaults to the
source title with (Clone) appended and description to the source description;
send either field to override it.

What is not copied: the clone is a new rule authored by you, so created_by is
your session member and the source rule's creation provenance
(created_by_reference_id / _type / _organization_id) and latest_hunt_run_id
are not carried over. Version history restarts at 1.

Status: the clone is always created inactive, for the same reason a new rule is
— it has no runs behind it. Trigger POST /rules/{rule_id}/runs on the clone, then
activate it with PATCH /rules/{rule_id}/set-status.

Validation: the clone is validated as if you had written it by hand, so a source
rule that predates a current validation rule can fail with 400 and the same
validation_errors payload as POST /rules. One legacy shape is repaired rather
than rejected: a positional organization_id = ? predicate is stripped, since
ClickHouse cannot parse it and every run is already scoped to its tenant.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Path Params
string
required

ID of the rule to clone

Body Params

Request model for POST /rules/{rule_id}/clone.

Everything that defines the rule is copied from the source, so the body only carries
the two fields a caller almost always wants to change on a copy. Status is not
settable: a clone has no runs behind it and starts inactive like any other new rule.

Title for the clone. Defaults to the source title with "(Clone)" appended.

Description for the clone. Defaults to the source rule's description.

Headers
string
required

Your API Key ID

string

Your API Key Secret

Responses

Language
Credentials
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json