# List all Rules Exceptions

**URL:** <https://discuss.elastic.co/t/list-all-rules-exceptions/365756>\
**Category:** SIEM\
**Created:** [August 29, 2024, 10:39am UTC](https://discuss.elastic.co/t/list-all-rules-exceptions/365756 "2024-08-29T10:39:13Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![aptfinf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aptfinf/32/137147_2.png) [@aptfinf](https://discuss.elastic.co/u/aptfinf)\
**Post date:** [August 29, 2024, 10:39am UTC](https://discuss.elastic.co/t/list-all-rules-exceptions/365756/1 "2024-08-29T10:39:13Z")

</div>

Hello to everyone.

I'm exploring Elastic Defend in a self-hosted cluster with Basic license.

I have a question: if i add a Rule Exception (without using Shared Exceptions Lists), is there a way to list all exceptions created or to list all rules that have exceptions configured?

I'm asking this because if i want to check all exceptions that i created after some time, i can't remember all rules name in which i added these exceptions, and therefore it's impossible to retrieve them.

Thanks in advance

---

<div class="post-metadata">

**Author:** ![Kseniiaign](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kseniiaign/32/105250_2.png) [@Kseniiaign](https://discuss.elastic.co/u/Kseniiaign)\
**Post date:** [August 29, 2024, 11:46am UTC](https://discuss.elastic.co/t/list-all-rules-exceptions/365756/2 "2024-08-29T11:46:21Z")

</div>

Hi @aptfinf , it is not possible at the moment, but it is something we plan to address. Thanks for the question.

---

<div class="post-metadata">

**Author:** ![aptfinf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aptfinf/32/137147_2.png) [@aptfinf](https://discuss.elastic.co/u/aptfinf)\
**Post date:** [August 29, 2024, 3:35pm UTC](https://discuss.elastic.co/t/list-all-rules-exceptions/365756/3 "2024-08-29T15:35:13Z")

</div>

Thank you for your answer.

As a workaround, is there maybe a query that i can execute directly on Elasticsearch, that allow me to see all exclusions?

---

<div class="post-metadata">

**Author:** ![vitaliidm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vitaliidm/32/101610_2.png) [@vitaliidm](https://discuss.elastic.co/u/vitaliidm)\
**Post date:** [August 29, 2024, 4:39pm UTC](https://discuss.elastic.co/t/list-all-rules-exceptions/365756/4 "2024-08-29T16:39:03Z")

</div>

hey @aptfinf

You can use this [API](https://www.elastic.co/guide/en/security/current/exceptions-api-find-exception-containers.html) to find all exception containers  
Results would have shared lists and exception container applied to a single rule.

To filter out exceptions applied to a single rule use filter in query

`exception_lists/_find?filter=(exception-list.attributes.type%3Arule_default)`

It will return exception container that has link to a rule id in description

```auto
...
description: "Exception list containing exceptions for rule with id: 5232af22-beb8-437d-852e-38784e075644"
...

```

If you need to look values of exceptions of any container, use [exception\_item API](https://www.elastic.co/guide/en/security/current/exceptions-api-find-exception-items.html)

Hope, that would help to resolve the question

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 26, 2024, 4:39pm UTC](https://discuss.elastic.co/t/list-all-rules-exceptions/365756/5 "2024-09-26T16:39:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
