Rule templates API
These endpoints list, create, change and apply rule templates, and save a scope's current rules as a new template. They do from a script what the Templates page does.
What a template is
A rule template is a named, ordered set of rules you can add to a rule scope (your global rules, or one machine's) in one step. See Rule templates for the page itself.
There are two kinds. Your own templates are created by you and seen only by you. EyalSec templates are published by EyalSec for every account: you can apply them but not change them.
Applying a template copies its rules into the scope. From then on they are ordinary rules: edit, disable or delete them like any other. Changing or deleting the template later does not touch rules already applied from it.
In the calls below, machine is a machine's public_id, or an empty string "" for your global rules.
List templates
GET /api/rule_templates/ lists every template you can see: your own and the EyalSec ones, each with its rules in order. It is a read.
GET /api/rule_templates/
{
"templates": [
{
"id": 3,
"owner": "eyalsec",
"name": "OWASP basics",
"description": "",
"items": [
{ "source": "socket", "event_pattern": "exec|eval",
"mode": 2, "sanitize_scope": "any", "position": 0 }
]
}
]
}
owner is me for your own templates and eyalsec for the published ones. The ready-made templates also carry product, the product whose events their rules are written for (for example "product": "python" for es-python); other templates have no product field. An item carries the same four fields a rule does: source, event_pattern, mode and sanitize_scope. It has no enabled flag (an applied rule is always enabled) and no polarity (it follows the mode).
Create a template
POST /api/rule_templates/create/ creates one of your own templates and answers 201 with it. It is a write.
POST /api/rule_templates/create/
JSON body: name (required, unique among your templates, ignoring case), description (optional) and items (the rules). Each item is checked exactly as creating a rule checks a rule, so a template can never hold a rule that would be refused. A missing sanitize_scope means any.
You can have at most 50 templates, with at most 200 items each.
curl -s https://eyalsec.com/api/rule_templates/create/ \
-H "X-API-Key: es2_EXAMPLEKEYdoNotUse0000000000000000000000" \
-H "Content-Type: application/json" \
-d '{"name":"My web app","items":[{"source":"socket","event_pattern":"exec|eval","mode":2}]}'
{ "id": 12, "owner": "me", "name": "My web app", "description": "",
"items": [ { "source": "socket", "event_pattern": "exec|eval", "mode": 2,
"sanitize_scope": "any", "position": 0 } ] }
Update a template
PATCH /api/rule_templates/{id}/update/ renames one of your templates and replaces its whole rule list. It is a write and answers 204.
PATCH /api/rule_templates/{id}/update/
It takes the same body as create. The items you send replace the old list, so include every rule you want to keep. A template that is not yours, which includes every EyalSec template, is a 404.
curl -s -X PATCH https://eyalsec.com/api/rule_templates/12/update/ \
-H "X-API-Key: es2_EXAMPLEKEYdoNotUse0000000000000000000000" \
-H "Content-Type: application/json" \
-d '{"name":"My web app","items":[{"source":"any","event_pattern":"eval","mode":2}]}'
Delete a template
DELETE /api/rule_templates/{id}/delete/ deletes one of your templates. It is a write and answers 204; rules already applied from it stay.
DELETE /api/rule_templates/{id}/delete/
A template that is not yours is a 404.
Apply a template
POST /api/rule_templates/{id}/apply/ adds a template's rules to a scope. It works on your own templates and on EyalSec ones, and it is a write. See applying a template.
POST /api/rule_templates/{id}/apply/
JSON body: machine, a public_id, or "" for your global rules.
curl -s https://eyalsec.com/api/rule_templates/3/apply/ \
-H "X-API-Key: es2_EXAMPLEKEYdoNotUse0000000000000000000000" \
-H "Content-Type: application/json" \
-d '{"machine":""}'
{ "added": 5, "skipped_raise": 2, "skipped_duplicate": 1 }
Nothing is replaced: the scope keeps its rules and the template's rules are added to them, enabled. Two kinds of item are skipped rather than added, and both are counted, so a partial apply is never silent:
skipped_duplicate: the scope already has a rule with the samesource,event_pattern,modeandsanitize_scope. Applying the same template twice adds nothing the second time.skipped_raise: the item is a Raise rule (mode 3) and Raise is not enabled for your account. The rest of the template still applies.
A template you cannot see is a 404.
Save a scope as a template
POST /api/rule_templates/snapshot/ saves the rules currently in a scope as a new template of your own and answers 201 with it. It is a write. See saving a scope as a template.
POST /api/rule_templates/snapshot/
JSON body: name (required), description (optional) and machine (a public_id, or "" for your global rules). Disabled rules are saved too, since a template item has no enabled flag. The same limits of 50 templates and 200 items apply.
curl -s https://eyalsec.com/api/rule_templates/snapshot/ \
-H "X-API-Key: es2_EXAMPLEKEYdoNotUse0000000000000000000000" \
-H "Content-Type: application/json" \
-d '{"name":"prod baseline","machine":""}'
{ "id": 13, "owner": "me", "name": "prod baseline", "description": "", "items": [] }