# How to get all rules from Elasticsearch Security using curl API?

**URL:** <https://discuss.elastic.co/t/how-to-get-all-rules-from-elasticsearch-security-using-curl-api/311618>\
**Category:** Elastic Security\
**Created:** [August 8, 2022, 4:43am UTC](https://discuss.elastic.co/t/how-to-get-all-rules-from-elasticsearch-security-using-curl-api/311618 "2022-08-08T04:43:09Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![xynobob](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xynobob/32/105064_2.png) [@xynobob](https://discuss.elastic.co/u/xynobob)\
**Post date:** [August 8, 2022, 4:43am UTC](https://discuss.elastic.co/t/how-to-get-all-rules-from-elasticsearch-security-using-curl-api/311618/1 "2022-08-08T04:43:09Z")

</div>

I have been trying to get all the rules (thousands of them) from my Elasticsearch Security using the curl API, however the only example and way shown on the website is able to obtain only one single rule at a time by running: `curl -X GET <ip address>:<port>/api/detection_engine/rules?rule_id=<rule_id>` and since it doesn't accept wildcards, I can't get what I want.  
So far, I am unable to get all the rules, only one single rule at a time which is undesirable to what I am achieving. Even tried using the \_find method which is to run `curl -X GET <ip address>:<port>/api/detection_engine/rules/_find?page=100&per_page=100`, I still didn't get what I want and in addition, this method added new fields to the curl result which I do not want.

---

<div class="post-metadata">

**Author:** ![Nikita\_Khristinin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikita_khristinin/32/102092_2.png) [@Nikita\_Khristinin](https://discuss.elastic.co/u/Nikita_Khristinin)\
**Post date:** [August 8, 2022, 10:02am UTC](https://discuss.elastic.co/t/how-to-get-all-rules-from-elasticsearch-security-using-curl-api/311618/2 "2022-08-08T10:02:01Z")

</div>

Hello @xynobob

Maybe [this API](https://www.elastic.co/guide/en/security/current/rules-api-find.html) call will help you. It allows you to get rules with pagination, but if you specify per\_page, you can probably get all your rules

`api/detection_engine/rules/_find?page=1&per_page=1000`

---

<div class="post-metadata">

**Author:** ![xynobob](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xynobob/32/105064_2.png) [@xynobob](https://discuss.elastic.co/u/xynobob)\
**Post date:** [August 8, 2022, 10:27am UTC](https://discuss.elastic.co/t/how-to-get-all-rules-from-elasticsearch-security-using-curl-api/311618/3 "2022-08-08T10:27:53Z")

</div>

Hi @Nikita_Khristinin thanks for the suggestion but, unfortunately this still doesn't get me all my rules as I have over 2000+ rules and if i changed to `&per_page=3000` , I will get this error:

```auto
{"message":"all shards failed: search_phase_execution_exception: [query_shard_exception] Reason: failed to create query: maxClauseCount is set to 1024","status_code":400}

```

Any ideas if there are any other ways to retrieve all my rules?

---

<div class="post-metadata">

**Author:** ![Nikita\_Khristinin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikita_khristinin/32/102092_2.png) [@Nikita\_Khristinin](https://discuss.elastic.co/u/Nikita_Khristinin)\
**Post date:** [August 16, 2022, 8:54am UTC](https://discuss.elastic.co/t/how-to-get-all-rules-from-elasticsearch-security-using-curl-api/311618/4 "2022-08-16T08:54:38Z")

</div>

> [@Nikita\_Khristinin](#):
>
> api/detection\_engine/rules/\_find?page=1&per\_page=1000

Will it help to send several requests like?

```auto
api/detection_engine/rules/_find?page=1&per_page=1000
api/detection_engine/rules/_find?page=2&per_page=1000
api/detection_engine/rules/_find?page=3&per_page=1000

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 13, 2022, 8:55am UTC](https://discuss.elastic.co/t/how-to-get-all-rules-from-elasticsearch-security-using-curl-api/311618/5 "2022-09-13T08:55:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
