Google Cloud Chronicle Rules API

Operations for managing detection rules

Operations 5

GET /projects/{projectId}/locations/{location}/instances/{instanceId}/rules Google Cloud Chronicle List detection rules #
POST /projects/{projectId}/locations/{location}/instances/{instanceId}/rules Google Cloud Chronicle Create a detection rule #
GET /projects/{projectId}/locations/{location}/instances/{instanceId}/rules/{ruleId} Google Cloud Chronicle Get a detection rule #
PATCH /projects/{projectId}/locations/{location}/instances/{instanceId}/rules/{ruleId} Google Cloud Chronicle Update a detection rule #
DELETE /projects/{projectId}/locations/{location}/instances/{instanceId}/rules/{ruleId} Google Cloud Chronicle Delete a detection rule #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/google-cloud-chronicle-rules-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

google-cloud-chronicle-rules-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Google Cloud Chronicle Alerts Rules API
  description: The Chronicle API provides programmatic access to Google Cloud's security analytics platform. It supports ingesting security telemetry, searching security data using UDM, managing detection rules, investigating alerts, and accessing threat intelligence.
  version: v1alpha
  contact:
    name: Google Cloud Support
    url: https://cloud.google.com/chronicle/docs/support
  termsOfService: https://cloud.google.com/terms
servers:
- url: https://chronicle.googleapis.com/v1alpha
  description: Production Server
security:
- oauth2: []
tags:
- name: Rules
  description: Operations for managing detection rules
paths:
  /projects/{projectId}/locations/{location}/instances/{instanceId}/rules:
    get:
      operationId: listRules
      summary: Google Cloud Chronicle List detection rules
      description: Lists detection rules in a Chronicle instance.
      tags:
      - Rules
      parameters:
      - $ref: '#/components/parameters/projectId'
      - $ref: '#/components/parameters/location'
      - $ref: '#/components/parameters/instanceId'
      - $ref: '#/components/parameters/pageSize'
      - $ref: '#/components/parameters/pageToken'
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListRulesResponse'
    post:
      operationId: createRule
      summary: Google Cloud Chronicle Create a detection rule
      description: Creates a new detection rule in a Chronicle instance.
      tags:
      - Rules
      parameters:
      - $ref: '#/components/parameters/projectId'
      - $ref: '#/components/parameters/location'
      - $ref: '#/components/parameters/instanceId'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Rule'
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Rule'
  /projects/{projectId}/locations/{location}/instances/{instanceId}/rules/{ruleId}:
    get:
      operationId: getRule
      summary: Google Cloud Chronicle Get a detection rule
      description: Gets a detection rule by resource name.
      tags:
      - Rules
      parameters:
      - $ref: '#/components/parameters/projectId'
      - $ref: '#/components/parameters/location'
      - $ref: '#/components/parameters/instanceId'
      - $ref: '#/components/parameters/ruleId'
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Rule'
    patch:
      operationId: updateRule
      summary: Google Cloud Chronicle Update a detection rule
      description: Updates an existing detection rule.
      tags:
      - Rules
      parameters:
      - $ref: '#/components/parameters/projectId'
      - $ref: '#/components/parameters/location'
      - $ref: '#/components/parameters/instanceId'
      - $ref: '#/components/parameters/ruleId'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Rule'
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Rule'
    delete:
      operationId: deleteRule
      summary: Google Cloud Chronicle Delete a detection rule
      description: Deletes a detection rule.
      tags:
      - Rules
      parameters:
      - $ref: '#/components/parameters/projectId'
      - $ref: '#/components/parameters/location'
      - $ref: '#/components/parameters/instanceId'
      - $ref: '#/components/parameters/ruleId'
      responses:
        '200':
          description: Successful response
components:
  parameters:
    location:
      name: location
      in: path
      required: true
      schema:
        type: string
    projectId:
      name: projectId
      in: path
      required: true
      schema:
        type: string
    ruleId:
      name: ruleId
      in: path
      required: true
      schema:
        type: string
    instanceId:
      name: instanceId
      in: path
      required: true
      schema:
        type: string
    pageToken:
      name: pageToken
      in: query
      schema:
        type: string
    pageSize:
      name: pageSize
      in: query
      schema:
        type: integer
  schemas:
    Rule:
      type: object
      properties:
        name:
          type: string
          description: The resource name of the rule
        text:
          type: string
          description: The YARA-L 2.0 rule text
        displayName:
          type: string
          description: Display name for the rule
        severity:
          type: string
          enum:
          - INFORMATIONAL
          - LOW
          - MEDIUM
          - HIGH
          - CRITICAL
        enabled:
          type: boolean
          description: Whether the rule is enabled
        createTime:
          type: string
          format: date-time
        updateTime:
          type: string
          format: date-time
    ListRulesResponse:
      type: object
      properties:
        rules:
          type: array
          items:
            $ref: '#/components/schemas/Rule'
        nextPageToken:
          type: string
  securitySchemes:
    oauth2:
      type: oauth2
      flows:
        authorizationCode:
          authorizationUrl: https://accounts.google.com/o/oauth2/auth
          tokenUrl: https://oauth2.googleapis.com/token
          scopes:
            https://www.googleapis.com/auth/cloud-platform: Full access to Google Cloud
externalDocs:
  description: Chronicle API Documentation
  url: https://cloud.google.com/chronicle/docs/reference/rest