# How to extract rules and connector using elastic API

**URL:** <https://discuss.elastic.co/t/how-to-extract-rules-and-connector-using-elastic-api/303477>\
**Category:** Endpoint Security\
**Created:** [April 28, 2022, 8:09am UTC](https://discuss.elastic.co/t/how-to-extract-rules-and-connector-using-elastic-api/303477 "2022-04-28T08:09:55Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![waelboss](https://avatars.discourse-cdn.com/v4/letter/w/34f0e0/32.png) [@waelboss](https://discuss.elastic.co/u/waelboss)\
**Post date:** [April 28, 2022, 8:09am UTC](https://discuss.elastic.co/t/how-to-extract-rules-and-connector-using-elastic-api/303477/1 "2022-04-28T08:09:55Z")

</div>

i want to export rules and connector from elastic using API  
i created this request :

curl -X POST -u elastic:pass [https://myHOST:9243/api/detection\_engine/rules/\_export?exclude\_export\_details=true](https://myHOST:9243/api/detection_engine/rules/_export?exclude_export_details=true) -H 'kbn-xsrf: true' -H 'Content-Type: application/json' -d'  
{  
"objects": [  
{  
"rule\_id":"73c903d0-b0dc-11ec-bf76-67173033ecd8"  
}  
]  
}  
' -o exported-rules.ndjson

but i'm getting error:

{"exported\_count":0,"exported\_rules\_count":0,"missing\_rules":[{"rule\_id":"73c903d0-b0dc-11ec-bf76-67173033ecd8"}],"missing\_rules\_count":1,"exported\_exception\_list\_count":0,"exported\_exception\_list\_item\_count":0,"missing\_exception\_list\_item\_count":0,"missing\_exception\_list\_items":,"missing\_exception\_lists":,"missing\_exception\_lists\_count":0}

and for connectors i didn't find in the documentation how to export them.  
could you please help with this case?

---

<div class="post-metadata">

**Author:** ![spong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spong/32/54343_2.png) [@spong](https://discuss.elastic.co/u/spong)\
**Post date:** [May 5, 2022, 9:53pm UTC](https://discuss.elastic.co/t/how-to-extract-rules-and-connector-using-elastic-api/303477/2 "2022-05-05T21:53:40Z")

</div>

Hey there @waelboss 👋

So looks like you've got the export request correct, but there's an issue exporting that specific `ruleId`. There's a few things to check out and some other options as well.

Things to verify:

- Is this the correct space? There is no space in the URL, so this request will only try to export rules from the `default` space.
- Is this a `custom` rule or `prebuilt` Elastic rule? Only `custom` rules are exportable at the moment, so you would need to duplicate the `prebuilt` rule for it to be exportable
- Double-check you're using the correct `rule_id` of the rule and not `id`
- Can you try this same request without the `objects` payload and see if all rules are exported?
- What stack version are you on?

Additional options:  
Depending on your version, as of I believe `8.2` there's a [bulk export API](https://www.elastic.co/guide/en/security/current/bulk-actions-rules-api.html#_request_url_9) you could try that might a bit more ergonomic. You can see this being called when exporting via the UI:

 ![Rules_-_Kibana](https://us1.discourse-cdn.com/elastic/original/3X/f/0/f0c9a57052109a6fa9283595117cda7bd2471f95.jpeg)

As for Connectors, as mentioned [in the docs](https://www.elastic.co/guide/en/security/current/rules-api-export.html#rules-api-export) (second callout) they can be exported via the UI following [this documentation](https://www.elastic.co/guide/en/kibana/master/action-types.html#importing-and-exporting-connectors), or via the API using the [Export Objects API](https://www.elastic.co/guide/en/kibana/current/saved-objects-api-export.html).

Let me know if any of the above helps!

Cheers!  
Garrett

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 2, 2022, 9:53pm UTC](https://discuss.elastic.co/t/how-to-extract-rules-and-connector-using-elastic-api/303477/3 "2022-06-02T21:53:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
