Create a rule in your organization.
One endpoint handles all supported rule_type values; the shape of content
must match the type (see request examples in this operation).
rule_type | content format | Notes |
|---|---|---|
sigma | YAML string or parsed Sigma object | Metadata can live in the YAML. |
atomic_sql | sql_query, optional entities, level | Sigma migration target. |
scheduled_sql | query, schedule, entities, optional throttle | Org placeholder optional. |
signal_combination | query, schedule, description | Internal portal org only. |
For scheduled_sql, the organization_id = ? placeholder is optional — per-org
scoping is applied at execution (the placeholder is still replaced per tenant when
present). signal_combination queries must contain organization_id = ?.
Organization ID: Omit organization_id to create under your session organization.
If provided, it must match your session — cross-tenant creates are rejected.
Global rules are created by signing in as NEBULOCK_INTERNAL_PORTAL_ORG_ID;
the legacy "*" marker is not accepted.
Status: Use inactive while iterating; set active when ready to deploy.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||