# How to duplicate a rule?

**URL:** <https://discuss.elastic.co/t/how-to-duplicate-a-rule/331042>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [April 28, 2023, 10:04am UTC](https://discuss.elastic.co/t/how-to-duplicate-a-rule/331042 "2023-04-28T10:04:24Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![ppic](https://avatars.discourse-cdn.com/v4/letter/p/3da27b/32.png) [@ppic](https://discuss.elastic.co/u/ppic)\
**Post date:** [April 28, 2023, 10:04am UTC](https://discuss.elastic.co/t/how-to-duplicate-a-rule/331042/1 "2023-04-28T10:04:24Z")

</div>

Hello,  
I have to create several rules-alerts that are very similar.  
Is there a way to duplicate (copy/paste) a rule ?  
Thank you.

---

<div class="post-metadata">

**Author:** ![jcger](https://avatars.discourse-cdn.com/v4/letter/j/6bbea6/32.png) [@jcger](https://discuss.elastic.co/u/jcger)\
**Post date:** [April 28, 2023, 10:21am UTC](https://discuss.elastic.co/t/how-to-duplicate-a-rule/331042/2 "2023-04-28T10:21:26Z")

</div>

Hi @ppic,

You can follow this instructions [Manage detection rules | Elastic Security Solution [8.7] | Elastic](https://www.elastic.co/guide/en/security/current/rules-ui-management.html#select-all-prebuilt-rules). We introduced it in version 8.6 but if you have a previous version or you prefer so, you should be able to to export, then re-import and specify to use different IDs. You can also “script” them using the Kibana APIs [Alerting APIs | Kibana Guide [8.7] | Elastic](https://www.elastic.co/guide/en/kibana/current/alerting-apis.html)

---

<div class="post-metadata">

**Author:** ![ppic](https://avatars.discourse-cdn.com/v4/letter/p/3da27b/32.png) [@ppic](https://discuss.elastic.co/u/ppic)\
**Post date:** [April 28, 2023, 3:32pm UTC](https://discuss.elastic.co/t/how-to-duplicate-a-rule/331042/3 "2023-04-28T15:32:40Z")

</div>

Hi Julian,  
Thank you for your suggestion. I forgot to specify I use v7.17.  
Then, I tried to export, following [Export rules | Elastic Security Solution [7.17] | Elastic](https://www.elastic.co/guide/en/security/7.17/rules-api-export.html)  
I tried something like the example in Kibana console:

```auto
POST api/detection_engine/rules/_export?exclude_export_details=true&file_name=exported_rules.ndjson
{
  "objects": [
    {
      "rule_id":"one_real_rule_id"
    },
    {
      "rule_id":"another_real_rule_id"
    }
  ]
}

```

and I got the response :

```auto
{
  "error" : "no handler found for uri [/api/detection_engine/rules/_export?pretty=true] and method [POST]"
}

```

same if I prefix with the kibanaBaseUrl  
I don't undestand...

If I try it with curl/cmd Dos

```auto
U:\>curl -X POST curl -X POST "https://edaas-noprod.kb.elasticaas.ocb.equant.com:9243/api/detection_engine/rules/_export?exclude_export_details=true&file_name=exported_rules.ndjson" {"objects":[{"rule_id":"f70bb740-e5a8-11ed-8a4c-fbb45f1592a1"},{"rule_id":"4ee06690-e44c-11ed-9d70-65711c1fe732"}]}

```

response :

```auto
{"statusCode":401,"error":"Unauthorized","message":"Unauthorized"}curl: (3) nested brace in URL position 10:
{objects:[{rule_id:f70bb740-e5a8-11ed-8a4c-fbb45f1592a1},{rule_id:4ee06690-e44c-11ed-9d70-65711c1fe732}]}
         ^

```

There is a kind of syntax error, but also a right issue.

I made other test from [Get rule API | Kibana Guide [7.17] | Elastic](https://www.elastic.co/guide/en/kibana/7.17/get-rule-api.html) with curl/cmd Dos:

```auto
> curl -X GET https://edaas-noprod.kb.elasticaas.ocb.equant.com:9243/api/alerting/rule/4ee06690-e44c-11ed-9d70-65711c1fe732

```

response :

```auto
{"statusCode":401,"error":"Unauthorized","message":"Unauthorized"}

```

it looks like a rights issue.  
Do you think the same ?  
Thank you.

---

<div class="post-metadata">

**Author:** ![jcger](https://avatars.discourse-cdn.com/v4/letter/j/6bbea6/32.png) [@jcger](https://discuss.elastic.co/u/jcger)\
**Post date:** [May 2, 2023, 9:36am UTC](https://discuss.elastic.co/t/how-to-duplicate-a-rule/331042/4 "2023-05-02T09:36:38Z")

</div>

Hi @ppic,

You can't access the kibana API through the Dev Console but you can use the Saved Objects UI. Check out this link [Create and manage rules | Kibana Guide [7.17] | Elastic](https://www.elastic.co/guide/en/kibana/7.17/create-and-manage-rules.html#importing-and-exporting-rules)

The curl issue is a rights issue, yes. You are missing the auth parameter in your curl request, check out this url [REST API | Kibana Guide [7.17] | Elastic](https://www.elastic.co/guide/en/kibana/7.17/api.html#api-authentication), it mentions the auth types available. You will also have to add these headers [REST API | Kibana Guide [7.17] | Elastic](https://www.elastic.co/guide/en/kibana/7.17/api.html#api-request-headers) to your request

---

<div class="post-metadata">

**Author:** ![ppic](https://avatars.discourse-cdn.com/v4/letter/p/3da27b/32.png) [@ppic](https://discuss.elastic.co/u/ppic)\
**Post date:** [May 2, 2023, 12:05pm UTC](https://discuss.elastic.co/t/how-to-duplicate-a-rule/331042/5 "2023-05-02T12:05:01Z")

</div>

Hi Julian,  
The UI export is perfect. Thank you.  
Best regards.

---

<div class="post-metadata">

**Author:** ![ppic](https://avatars.discourse-cdn.com/v4/letter/p/3da27b/32.png) [@ppic](https://discuss.elastic.co/u/ppic)\
**Post date:** [May 5, 2023, 2:48pm UTC](https://discuss.elastic.co/t/how-to-duplicate-a-rule/331042/6 "2023-05-05T14:48:48Z")

</div>

Hi Julian,

OK, I can export the rules, but the initial goal is to duplicate easily the rules with slight changes between them.  
I made two alerts about two http test, only the URLs differs.  
I have a dozen URLs to test.  
I guess I can duplicate the export, change some values and import.  
I made a comparizon between both exports.  
The differences are in :

- the fields containing the URL ==\> I change the URL
- date time fields (created, executed...)... ==\> I think I can keep the same. OK ?
- version
- id

Which values should I put for "version" and "id" (and the dates, if they have to be changed) ?

---

<div class="post-metadata">

**Author:** ![jcger](https://avatars.discourse-cdn.com/v4/letter/j/6bbea6/32.png) [@jcger](https://discuss.elastic.co/u/jcger)\
**Post date:** [May 10, 2023, 12:06pm UTC](https://discuss.elastic.co/t/how-to-duplicate-a-rule/331042/7 "2023-05-10T12:06:22Z")

</div>

Hi @ppic ,

You should be fine keeping the version but remove the id. When importing select "Create new objects with random IDs" so it generates an id for you.

---

<div class="post-metadata">

**Author:** ![ppic](https://avatars.discourse-cdn.com/v4/letter/p/3da27b/32.png) [@ppic](https://discuss.elastic.co/u/ppic)\
**Post date:** [May 10, 2023, 12:40pm UTC](https://discuss.elastic.co/t/how-to-duplicate-a-rule/331042/8 "2023-05-10T12:40:13Z")

</div>

Hi Julian,

Perfect !  
Thank you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 7, 2023, 12:40pm UTC](https://discuss.elastic.co/t/how-to-duplicate-a-rule/331042/9 "2023-06-07T12:40:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
