post
https://example.com/public/v1/rules
Create a rule in your organization.
One endpoint handles all supported rule_type values; the shape of content
must match the type (see request examples in this operation).
rule_type | content format | Notes |
|---|---|---|
sigma | YAML string or parsed Sigma object | Title/description/tags can live in the YAML. |
scheduled_sql | Object with query, schedule, entity_fields | Query must contain organization_id = ?. |
signal_combination | Object with query, schedule, description | Customer portal org only on this API. |
Organization ID: External callers should omit organization_id — the rule is
created under the organization in your session. Internal portal sessions may pass
organization_id (use "*" for cross-tenant rules when omitted on internal portal).
Status: Use inactive while iterating; set active when ready to deploy.
Recent Requests
Log in to see full request history
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||
Loading…