get_correlation_rule
Retrieve the complete definition of a correlation rule by its ID, including conditions and groupings.
Instructions
Get the full definition of a correlation rule by id (where/afterEvents/groupBy/...). server: which configured server to target (default active/default).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| server | No | ||
| rule_id | Yes |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |