# Get events of an specific rule

**URL:** <https://discuss.elastic.co/t/get-events-of-an-specific-rule/304073>\
**Category:** SIEM\
**Tags:** elastic-stack-alerting\
**Created:** [May 5, 2022, 11:17pm UTC](https://discuss.elastic.co/t/get-events-of-an-specific-rule/304073 "2022-05-05T23:17:37Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Felipe\_Fuller](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/felipe_fuller/32/80377_2.png) [@Felipe\_Fuller](https://discuss.elastic.co/u/Felipe_Fuller)\
**Post date:** [May 5, 2022, 11:17pm UTC](https://discuss.elastic.co/t/get-events-of-an-specific-rule/304073/1 "2022-05-05T23:17:37Z")

</div>

Hi Community!

I'm trying to obtain all the events of a specific rule. Since I didn't find an API that does the job, I inspected the Chome Network Dev tool. During the inspection, I saw a request done to `/internal/bsearch` which replies with the events. The problem is that the reply is encrypted, and it comes with the following format:

```auto
eJzsvelyG9f16 ... es=

```

How can I decrypt/decode or manage that encryption? Because clearly is being decrypted on the user side. Is there any better way to approach this?

Thank you in advance!

Best,

Felipe

---

<div class="post-metadata">

**Author:** ![spong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spong/32/54343_2.png) [@spong](https://discuss.elastic.co/u/spong)\
**Post date:** [May 5, 2022, 11:48pm UTC](https://discuss.elastic.co/t/get-events-of-an-specific-rule/304073/2 "2022-05-05T23:48:55Z")

</div>

Oh hey there @Felipe_Fuller 👋, thanks for the question! 🙂

So we actually have a dedicated API for fetching alerts, but you may've missed it since there was a renaming event and it goes by the `signals` moniker instead of alerts. You can see all the details for that API here: [Signals endpoint | Elastic Security Solution [8.2] | Elastic](https://www.elastic.co/guide/en/security/current/signals-api-overview.html). Should be as simple as hitting that API with an ES Query DSL matching a specific rule name/id.

As for that `bsearch` request you've inspected, IIRC the response is just compressed (not encrypted). I believe there's a `kibana.yml` configuration for disabling this:

```auto
uiSettings:
  overrides:
    'bfetch:disableCompression': true

```

Of course you'll probably only want to enable for debugging purposes to ensure network traffic doesn't balloon.

Hope this helps -- cheers!  
Garrett

---

<div class="post-metadata">

**Author:** ![Kevin\_Qualters](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevin_qualters/32/78907_2.png) [@Kevin\_Qualters](https://discuss.elastic.co/u/Kevin_Qualters)\
**Post date:** [May 6, 2022, 1:34am UTC](https://discuss.elastic.co/t/get-events-of-an-specific-rule/304073/3 "2022-05-06T01:34:24Z")

</div>

@Felipe_Fuller if you want to make the same request and have the response come back uncompressed, you can right click the response in chrome dev tools -\> copy as curl and manually remove the ?compress=true query param from the end of the url. Also, if you want to programmatically decompress it, here's a snippet that would do so:

```auto
import { unzlibSync, strFromU8 } from 'fflate';
import { toByteArray } from 'base64-js';

const input = process.argv[2];
const result = strFromU8(unzlibSync(toByteArray(input)));

console.log(result);

```

if that's index.js, you can run it with `node index.js compressedData`

---

<div class="post-metadata">

**Author:** ![Felipe\_Fuller](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/felipe_fuller/32/80377_2.png) [@Felipe\_Fuller](https://discuss.elastic.co/u/Felipe_Fuller)\
**Post date:** [May 6, 2022, 2:43am UTC](https://discuss.elastic.co/t/get-events-of-an-specific-rule/304073/4 "2022-05-06T02:43:16Z")

</div>

Thank you both very much, I will try the respective solutions! It's great having this kind of support!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 3, 2022, 2:43am UTC](https://discuss.elastic.co/t/get-events-of-an-specific-rule/304073/5 "2022-06-03T02:43:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
