Elastic Stack (ELK Stack) Security Detections API

Use the detections APIs to create and manage detection rules. Detection rules search events and external alerts sent to Elastic Security and generate detection alerts from any hits. Alerts are displayed on the **Alerts** page and can be assigned and triaged, using the alert status to mark them as open, closed, or acknowledged. This API supports both key-based authentication and basic authentication. To use key-based authentication, create an API key, then specify the key in the header of your API calls. To use basic authentication, provide a username and password; this automatically creates an API key that matches the current user’s privileges. In both cases, the API key is subsequently used for authorization when the rule runs. > warn > If the API key used for authorization has different privileges than the key that created or most recently updated a rule, the rule behavior might change. > If the API key that created a rule is deleted, or the user that created the rule becomes inactive, the rule will stop running. To create and run rules, the user must meet specific requirements for the Kibana space. Refer to the [Detections requirements](https://www.elastic.co/guide/en/security/current/detections-permissions-section.html) for a complete list of requirements.

Business capability
Threat Detection & Response Management BC-620.30

Operations 29

POST /api/detection_engine/attacks/assignees Assign and unassign users from attack discovery alerts #
POST /api/detection_engine/attacks/search Find and/or aggregate attack discovery alerts #
POST /api/detection_engine/attacks/status Set attack discovery alerts workflow status #
POST /api/detection_engine/attacks/tags Add and remove attack discovery alert tags #
DELETE /api/detection_engine/index Delete an alerts index #
GET /api/detection_engine/index Reads the alert index name if it exists #
POST /api/detection_engine/index Create an alerts index #
GET /api/detection_engine/privileges Returns user privileges for the Kibana space #
DELETE /api/detection_engine/rules Delete a detection rule #
GET /api/detection_engine/rules Retrieve a detection rule #
PATCH /api/detection_engine/rules Patch a detection rule #
POST /api/detection_engine/rules Create a detection rule #
PUT /api/detection_engine/rules Update a detection rule #
POST /api/detection_engine/rules/_bulk_action Apply a bulk action to detection rules #
POST /api/detection_engine/rules/_export Export detection rules #
GET /api/detection_engine/rules/_find List all detection rules #
POST /api/detection_engine/rules/_import Import detection rules #
PUT /api/detection_engine/rules/prepackaged Install prebuilt detection rules and Timelines #
GET /api/detection_engine/rules/prepackaged/_status Retrieve the status of prebuilt detection rules and Timelines #
POST /api/detection_engine/rules/preview Preview rule alerts generated on specified time range #
POST /api/detection_engine/signals/assignees Assign and unassign users from detection alerts #
POST /api/detection_engine/signals/finalize_migration Finalize detection alert migrations #
DELETE /api/detection_engine/signals/migration Clean up detection alert migrations #
POST /api/detection_engine/signals/migration Initiate a detection alert migration #
GET /api/detection_engine/signals/migration_status Retrieve the status of detection alert migrations #
POST /api/detection_engine/signals/search Find and/or aggregate detection alerts #
POST /api/detection_engine/signals/status Set a detection alert status #
POST /api/detection_engine/signals/tags Add and remove detection alert tags #
GET /api/detection_engine/tags List all detection rule tags #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/elk-stack-security-detections-api-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

elk-stack-security-detections-api-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  contact:
    name: Kibana Team
  description: The Kibana REST APIs enable you to manage resources such as connectors, data views, and saved objects.
  title: Kibana Security Detections API
  version: ''
  x-doc-license:
    name: Attribution-NonCommercial-NoDerivatives 4.0 International
    url: https://creativecommons.org/licenses/by-nc-nd/4.0/
  x-feedbackLink:
    label: Feedback
    url: https://github.com/elastic/docs-content/issues/new?assignees=&labels=feedback%2Ccommunity&projects=&template=api-feedback.yaml&title=%5BFeedback%5D%3A+
servers:
- url: https://{kibana_url}
  variables:
    kibana_url:
      default: localhost:5601
security:
- apiKeyAuth: []
- basicAuth: []
tags:


# --- truncated at 32 KB (482 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/elk-stack/refs/heads/main/openapi/elk-stack-security-detections-api-api-openapi.yml