# Exporting rules to ndjson generates incomplete file

**URL:** <https://discuss.elastic.co/t/exporting-rules-to-ndjson-generates-incomplete-file/318214>\
**Category:** SIEM\
**Created:** [November 4, 2022, 8:02pm UTC](https://discuss.elastic.co/t/exporting-rules-to-ndjson-generates-incomplete-file/318214 "2022-11-04T20:02:46Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ElasticUser11](https://avatars.discourse-cdn.com/v4/letter/e/ee59a6/32.png) [@ElasticUser11](https://discuss.elastic.co/u/ElasticUser11)\
**Post date:** [November 4, 2022, 8:02pm UTC](https://discuss.elastic.co/t/exporting-rules-to-ndjson-generates-incomplete-file/318214/1 "2022-11-04T20:02:46Z")

</div>

I'm trying to export all the 722 rules into an ndjson file, but the file is incomplete. There are two sets of rule: Elastic rules and Custom rules.

I go to Security \> Overview \> Rules \> Select all 722 rules \> Bulk Actions \> Export selected.

 ![1111](https://us1.discourse-cdn.com/elastic/original/3X/9/6/963049b53dbcac1e3c061627ce485c552aa7215c.png)

However, the resulting output contains the following, which is NOT what I need.

This is what I get when selecting Elastic rules:

 ![11](https://us1.discourse-cdn.com/elastic/original/3X/f/f/ffb0dc10d61d8065bb6015c0297edf733506590b.png)

This is what I get when selecting the 20 Custom rules, which is the output I need:

 ![111](https://us1.discourse-cdn.com/elastic/original/3X/d/5/d5b181875f70219ae4f680a09974d64ad65e939c.png)

Any idea on how to fix this? Or am I doing something wrong?

Thanks for your help!

---

<div class="post-metadata">

**Author:** ![georgii](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/georgii/32/78076_2.png) [@georgii](https://discuss.elastic.co/u/georgii)\
**Post date:** [November 8, 2022, 12:00pm UTC](https://discuss.elastic.co/t/exporting-rules-to-ndjson-generates-incomplete-file/318214/2 "2022-11-08T12:00:37Z")

</div>

@ElasticUser11 As of now, exporting prebuilt Elastic rules is not supported. Users can export only custom rules.

This is why you get the `"exported_rules_count":0` in the ndjson file when you select `Elastic rules (702)` and try to export them.

Can you please share why would you need to export prebuilt rules?

---

<div class="post-metadata">

**Author:** ![ElasticUser11](https://avatars.discourse-cdn.com/v4/letter/e/ee59a6/32.png) [@ElasticUser11](https://discuss.elastic.co/u/ElasticUser11)\
**Post date:** [November 8, 2022, 3:01pm UTC](https://discuss.elastic.co/t/exporting-rules-to-ndjson-generates-incomplete-file/318214/3 "2022-11-08T15:01:39Z")

</div>

We wanted to created a script containing the rules, descriptions, and tags to analyze the query structure and possibly improve them. We could do that manually, copying and pasting each one of them (722 x 3) is a bit discouraging, hence the exporting.

---

<div class="post-metadata">

**Author:** ![georgii](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/georgii/32/78076_2.png) [@georgii](https://discuss.elastic.co/u/georgii)\
**Post date:** [November 8, 2022, 3:47pm UTC](https://discuss.elastic.co/t/exporting-rules-to-ndjson-generates-incomplete-file/318214/4 "2022-11-08T15:47:12Z")

</div>

@ElasticUser11 If you need to fetch your rules as JSON to do some analysis on them, maybe you could use the `rules/_find` endpoint? This endpoint can return both prebuilt and custom rules.

> **[Find rules | Elastic Security Solution \[8.5\] | Elastic](https://www.elastic.co/guide/en/security/current/rules-api-find.html)**

Just specify a big enough `per_page` parameter to fetch all of them in a single request.

---

<div class="post-metadata">

**Author:** ![ElasticUser11](https://avatars.discourse-cdn.com/v4/letter/e/ee59a6/32.png) [@ElasticUser11](https://discuss.elastic.co/u/ElasticUser11)\
**Post date:** [November 9, 2022, 2:52pm UTC](https://discuss.elastic.co/t/exporting-rules-to-ndjson-generates-incomplete-file/318214/5 "2022-11-09T14:52:06Z")

</div>

That's perfect! Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 7, 2022, 2:52pm UTC](https://discuss.elastic.co/t/exporting-rules-to-ndjson-generates-incomplete-file/318214/6 "2022-12-07T14:52:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
