Clone a rule into a new rule in your organization.
The source rule must exist in your session organization; a rule owned by another
tenant returns 404. The new rule is returned in full, exactly as
GET /rules/{rule_id} would return it, with a fresh rule_id at version 1.
Supported rule types: atomic_sql and scheduled_sql. Other types return 400.
What is copied: content, severity, tags, detection_categories,
data_sources and rule_details come from the source rule. title defaults to the
source title with (Clone) appended and description to the source description;
send either field to override it.
What is not copied: the clone is a new rule authored by you, so created_by is
your session member and the source rule's creation provenance
(created_by_reference_id / _type / _organization_id) and latest_hunt_run_id
are not carried over. Version history restarts at 1.
Status: the clone is always created inactive, for the same reason a new rule is
— it has no runs behind it. Trigger POST /rules/{rule_id}/runs on the clone, then
activate it with PATCH /rules/{rule_id}/set-status.
Validation: the clone is validated as if you had written it by hand, so a source
rule that predates a current validation rule can fail with 400 and the same
validation_errors payload as POST /rules. One legacy shape is repaired rather
than rejected: a positional organization_id = ? predicate is stripped, since
ClickHouse cannot parse it and every run is already scoped to its tenant.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||