View as Markdown
Elastic Security icon

Elastic Security ACTION

Find Detection Rules

Find and list Elastic Security detection rules via GET /api/detection_engine/rules/_find, or fetch a single rule directly via GET /api/detection_engine/rules when id or ruleId is provided. Use this to search/browse rules, or to look up one rule's full definition once you have an ID. Run this first to obtain an id/ruleId before using Create or Update Detection Rule, Run Detection Rule, or Delete Record. Example: calling with filter: 'alert.attributes.enabled: true' returns { total: 3, data: [{ id: "7ac3...", name: "InGen Perimeter Query Rule", type: "query", enabled: true, ... }] }; use fields to shrink each rule down to just the fields you need — rule objects carry many advanced fields (exceptions_list, related_integrations, threat, etc.) that are rarely relevant. See the documentation
  • Action
  • Read only
  • API key
  • SDK
  • MCP

IMPLEMENTATION

Call this tool

Connect a user's Elastic Security account once, then configure and run Find Detection Rules from your backend or agent.

import { PipedreamClient } from "@pipedream/sdk"

const pd = new PipedreamClient({
  projectId: process.env.PIPEDREAM_PROJECT_ID!,
  clientId: process.env.PIPEDREAM_CLIENT_ID!,
  clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
  projectEnvironment: "production",
})

const result = await pd.actions.run({
  id: "elastic_security-find-detection-rules",
  externalUserId: "{external_user_id}", // any stable ID for this user in your system
  configuredProps: {
    elastic_security: { authProvisionId: "apn_xxxxxxx" },
    id: "Rule ID",
    ruleId: "Rule ID (User-defined)",
  },
})

console.log(result)

SCHEMA

Inputs

Pipedream supplies the connected account. Your application provides the operation-specific values below. Dynamic inputs are resolved against that user's account.

Find Detection Rules inputs
Property Type Description
id Rule ID string
Fetch a single rule directly by its Kibana internal UUID instead of searching. Provide either this or ruleId, not both. When set, all filter/sort/pagination parameters are ignored.
Optional
ruleId Rule ID (User-defined) string
Fetch a single rule directly by its user-defined rule_id instead of searching. Provide either this or id, not both. When set, all filter/sort/pagination parameters are ignored.
Optional
filter Filter string
KQL/Lucene filter over rule attributes using the alert.attributes.<field> syntax (e.g. alert.attributes.name: "My Rule" or alert.attributes.enabled: true). Ignored when id/ruleId is provided.
Optional
sortField Sort Field string
Field to sort by. One of: created_at, createdAt, enabled, name, risk_score, riskScore, severity, updated_at, updatedAt. Ignored when id/ruleId is provided.
Optional
sortOrder Sort Order string
Sort direction: asc or desc. Ignored when id/ruleId is provided.
Optional
page Page integer
Page number of results to return, starting at 1. Defaults to 1. If the response's total field exceeds page × perPage, more results exist — call again with page incremented by 1 to fetch them.
Optional
perPage Per Page integer
Number of results per page. Maximum 100. Defaults to 20. See Page for how to fetch additional pages.
Optional
fields Fields string[]
Only include these fields in each returned rule, to reduce response size. Omit to return the full rule object(s). Common fields: id, rule_id, name, description, type, enabled, risk_score, severity, tags, query, index, interval, created_at, updated_at.
Optional

REFERENCE

Tool details

Behavior hints are published with the component in the Pipedream registry and surface as MCP tool annotations, so an agent can reason about a tool before it calls it.

Registry key
elastic_security-find-detection-rules
Version
0.0.1
App
Elastic Security
Authentication
API key
Read-only
Yes
Destructive
No
Open world
Yes