Validate rule

Validate a rule (MQL, YAML fields, etc). When run against the sandbox or analyzer, no auth is needed but custom lists etc will not be available.

Body Params
action_ids
array of strings

IDs of actions to run when the rule is triggered

action_ids
boolean

Activate the rule immediately

attack_types
array of strings

Rule attack types

attack_types
authors
array of objects

Rule authors. Defaults to the user that made the request

authors
boolean

Whether auto-reviewed messages will be shared

string | null

The classification auto-reviewed messages will have, when an auto-review action is associated with the rule

string

Description of rule

detection_methods
array of strings

Rule detection technologies

detection_methods
false_positives
array of strings

Descriptions of known false positives that could occur

false_positives
string | null

Rule label

string | null

Rule maturity

string
required

Rule name

boolean

For internal usage only

references
array of strings

URL references

references
string | null

Rule severity

string
required

Source

tactics_and_techniques
array of strings

Rule tactics and techniques

tactics_and_techniques
tags
array of strings

Tags

tags
boolean | null

For Triage rules only, whether this rule will run for reported messages. For triage rules, one triage_ field must be true.

boolean | null

For Triage rules only, whether this rule will run for messages when ASA finishes processing on them. For triage rules, one triage_ field must be true.

boolean | null

For Triage rules only, whether this rule will run for messages whose classification has just changed. For triage rules, one triage_ field must be true.

boolean | null

For Triage rules only, whether this rule will run for messages which flagged. For triage rules, one triage_ field must be true.

string

Type of the rule

user_provided_tags
array of strings

User-provided tags

user_provided_tags
Response

Language
Credentials
URL
Choose an example:
application/json