# Importing rules with detection\_rules CLI

**URL:** <https://discuss.elastic.co/t/importing-rules-with-detection-rules-cli/327190>\
**Category:** Elastic Security\
**Created:** [March 7, 2023, 2:26pm UTC](https://discuss.elastic.co/t/importing-rules-with-detection-rules-cli/327190 "2023-03-07T14:26:10Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Fredrick](https://avatars.discourse-cdn.com/v4/letter/f/a5b964/32.png) [@Fredrick](https://discuss.elastic.co/u/Fredrick)\
**Post date:** [March 7, 2023, 2:26pm UTC](https://discuss.elastic.co/t/importing-rules-with-detection-rules-cli/327190/1 "2023-03-07T14:26:10Z")

</div>

Hello!

I've been recently importing rules with detection\_rules - [detection-rules/CLI.md at main · elastic/detection-rules · GitHub](https://github.com/elastic/detection-rules/blob/main/CLI.md#importing-rules-into-the-repo). My usecase is to convert our custom Kibana rules into toml files so we can manage our custom rules via configuration files.

I noticed the CLI tool only imports the required fields. All other fields such as tags, exceptions, to, from, interval, enabled are not imported.

Is there a way to import all the fields (both required and optional) with the detection\_rules CLI tool?

Thanks,

---

<div class="post-metadata">

**Author:** ![spong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spong/32/54343_2.png) [@spong](https://discuss.elastic.co/u/spong)\
**Post date:** [March 9, 2023, 10:35pm UTC](https://discuss.elastic.co/t/importing-rules-with-detection-rules-cli/327190/2 "2023-03-09T22:35:55Z")

</div>

Hey there @Fredrick, thanks for reporting this issue!

It definitely should be importing all schema valid fields, so I went ahead and opened up a [github issue](https://github.com/elastic/detection-rules/issues/2641) over in the detection-rules repo for them to dig in further and hopefully get a fix in. Please follow that issue for updates.

One last question, what stack version are you trying to import these into? Just in case there's a stack API issue we need to look into as well.

Thanks!  
Garrett

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 6, 2023, 10:36pm UTC](https://discuss.elastic.co/t/importing-rules-with-detection-rules-cli/327190/3 "2023-04-06T22:36:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
