> ## Documentation Index
> Fetch the complete documentation index at: https://docs.blinkops.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create Rules

Creates multiple rules.

## Basic Parameters

<div className="integrations-table">
  | Parameter  | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
  | ---------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
  | Rules List | List of rules represented by json objects to create.<br /><br />For example, here's a list of one rule:<br /><pre><code>\[<br />  \{<br />    "kind": "it:rule:detection",<br />    "predicate": \{<br />      "id": "b73fc7b3-af84-48b6-bb2f-f3afd115a453",<br />      "definition": \{},<br />      "patterns": \[<br />        \{}<br />      ],<br />      "predicates": \[<br />        \{}<br />      ],<br />      "lists": \[<br />        \{}<br />      ]<br />    },<br />    "actions": \[<br />      \[<br />        \{<br />          "kind": "it:rule:action:kind:incident",<br />          "parameters": \{<br />            "probability": 0.15,<br />            "impact": 0.1,<br />            "score": 0.015,<br />            "urgency": 0.2,<br />            "severity": "incident:severity:100:low"<br />          }<br />        },<br />        \{<br />          "kind": "it:rule:action:kind:notification",<br />          "parameters": \{<br />            "target": \{<br />              "id": "someUUID"<br />            }<br />          }<br />        }<br />      ],<br />      \[<br />        \{<br />          "kind": "it:rule:action:kind:incident",<br />          "parameters": \{<br />            "probability": 0.15,<br />            "impact": 0.1,<br />            "score": 0.015,<br />            "urgency": 0.2,<br />            "severity": "incident:severity:100:low"<br />          }<br />        },<br />        \{<br />          "kind": "it:rule:action:kind:notification",<br />          "parameters": \{<br />            "target": \{<br />              "id": "someUUID"<br />            }<br />          }<br />        }<br />      ],<br />      \[<br />        \{<br />          "kind": "it:rule:action:kind:incident",<br />          "parameters": \{<br />            "probability": 0.15,<br />            "impact": 0.1,<br />            "score": 0.015,<br />            "urgency": 0.2,<br />            "severity": "incident:severity:100:low"<br />          }<br />        },<br />        \{<br />          "kind": "it:rule:action:kind:notification",<br />          "parameters": \{<br />            "target": \{<br />              "id": "someUUID"<br />            }<br />          }<br />        }<br />      ],<br />      \[<br />        \{<br />          "kind": "it:rule:action:kind:incident",<br />          "parameters": \{<br />            "probability": 0.15,<br />            "impact": 0.1,<br />            "score": 0.015,<br />            "urgency": 0.2,<br />            "severity": "incident:severity:100:low"<br />          }<br />        },<br />        \{<br />          "kind": "it:rule:action:kind:notification",<br />          "parameters": \{<br />            "target": \{<br />              "id": "someUUID"<br />            }<br />          }<br />        }<br />      ],<br />      \[<br />        \{<br />          "kind": "it:rule:action:kind:incident",<br />          "parameters": \{<br />            "probability": 0.15,<br />            "impact": 0.1,<br />            "score": 0.015,<br />            "urgency": 0.2,<br />            "severity": "incident:severity:100:low"<br />          }<br />        },<br />        \{<br />          "kind": "it:rule:action:kind:notification",<br />          "parameters": \{<br />            "target": \{<br />              "id": "someUUID"<br />            }<br />          }<br />        }<br />      ],<br />      \[<br />        \{<br />          "kind": "it:rule:action:kind:incident",<br />          "parameters": \{<br />            "probability": 0.15,<br />            "impact": 0.1,<br />            "score": 0.015,<br />            "urgency": 0.2,<br />            "severity": "incident:severity:100:low"<br />          }<br />        },<br />        \{<br />          "kind": "it:rule:action:kind:notification",<br />          "parameters": \{<br />            "target": \{<br />              "id": "someUUID"<br />            }<br />          }<br />        }<br />      ],<br />      \[<br />        \{<br />          "kind": "it:rule:action:kind:incident",<br />          "parameters": \{<br />            "probability": 0.15,<br />            "impact": 0.1,<br />            "score": 0.015,<br />            "urgency": 0.2,<br />            "severity": "incident:severity:100:low"<br />          }<br />        },<br />        \{<br />          "kind": "it:rule:action:kind:notification",<br />          "parameters": \{<br />            "target": \{<br />              "id": "someUUID"<br />            }<br />          }<br />        }<br />      ],<br />      \[<br />        \{<br />          "kind": "it:rule:action:kind:incident",<br />          "parameters": \{<br />            "probability": 0.15,<br />            "impact": 0.1,<br />            "score": 0.015,<br />            "urgency": 0.2,<br />            "severity": "incident:severity:100:low"<br />          }<br />        },<br />        \{<br />          "kind": "it:rule:action:kind:notification",<br />          "parameters": \{<br />            "target": \{<br />              "id": "someUUID"<br />            }<br />          }<br />        }<br />      ],<br />      \[<br />        \{<br />          "kind": "it:rule:action:kind:incident",<br />          "parameters": \{<br />            "probability": 0.15,<br />            "impact": 0.1,<br />            "score": 0.015,<br />            "urgency": 0.2,<br />            "severity": "incident:severity:100:low"<br />          }<br />        },<br />        \{<br />          "kind": "it:rule:action:kind:notification",<br />          "parameters": \{<br />            "target": \{<br />              "id": "someUUID"<br />            }<br />          }<br />        }<br />      ],<br />      \[<br />        \{<br />          "kind": "it:rule:action:kind:incident",<br />          "parameters": \{<br />            "probability": 0.15,<br />            "impact": 0.1,<br />            "score": 0.015,<br />            "urgency": 0.2,<br />            "severity": "incident:severity:100:low"<br />          }<br />        },<br />        \{<br />          "kind": "it:rule:action:kind:notification",<br />          "parameters": \{<br />            "target": \{<br />              "id": "someUUID"<br />            }<br />          }<br />        }<br />      ]<br />    ],<br />    "target": \{<br />      "defaults": \[<br />        \{<br />          "kind": "endpoint:agent",<br />          "overlay": true<br />        }<br />      ],<br />      "realms": \[<br />        \{<br />          "id": "b73fc7b3-af84-48b6-bb2f-f3afd115a453",<br />          "overlay": true<br />        }<br />      ]<br />    },<br />    "options": \{<br />      "filter": \{<br />        "simple": \{<br />          "include": \[<br />            \{<br />              "activity.clumps.primary.item.designations": \[<br />                "it:activity:clump:item:first",<br />                "it:activity:clump:item:intermediate",<br />                "it:activity:clump:item:last"<br />              ]<br />            }<br />          ]<br />        }<br />      }<br />    },<br />    "details": \{<br />      "name": "USA Part Codes",<br />      "description": "Two-letter codes of all USA parts including states, territories and the DC"<br />    },<br />    "alias": "USA\_PART\_CODES",<br />    "iver": 319,<br />    "sver": "1.2.3",<br />    "createdAt": "2018-04-12T16:36:51.700Z",<br />    "createdBy": \{<br />      "principal": \{<br />        "id": "b73fc7b3-af84-48b6-bb2f-f3afd115a453"<br />      }<br />    },<br />    "updatedAt": "2018-04-12T16:36:51.700Z",<br />    "updatedBy": \{<br />      "principal": \{<br />        "id": "b73fc7b3-af84-48b6-bb2f-f3afd115a453"<br />      }<br />    },<br />    "tenant": 123456789,<br />    "extent": "tenant",<br />    "status": "active",<br />    "tags": \[<br />      "rules",<br />      "windows",<br />      "agent"<br />    ],<br />    "id": "b73fc7b3-af84-48b6-bb2f-f3afd115a453"<br />  }<br />]</code></pre> |
</div>

## Advanced Parameters

<div className="integrations-table">
  | Parameter      | Description                                   |
  | -------------- | --------------------------------------------- |
  | Consistency    | Return when data is ready for read or query.  |
  | Correlation ID | ID to correlate multiple requests.            |
  | Timeout        | Time to wait before consistency=query throws. |
  | Transaction ID | ID for a transaction.                         |
</div>

## Example Output

```json theme={"dark"}
{
	"_status": {
		"status": 0,
		"code": "string"
	},
	"_meta": {
		"stats": {
			"offset": 0,
			"limit": 0,
			"total": 0
		},
		"origin": {}
	},
	"data": [
		"string"
	]
}
```

## Workflow Library Example

[Create Rules with Proofpoint Itm and Send Results Via Email](https://library.blinkops.com/workflows/create-rules-with-proofpoint-itm-and-send-results-via-email)

<div className="iframe-wrapper">
  <div className="iframe-media">
    <img src="https://mintcdn.com/blinkops-2/ojHYuDeYX5FWuN8a/img/Icons/play-box.svg?fit=max&auto=format&n=ojHYuDeYX5FWuN8a&q=85&s=b8af968e71438a9499c3223c9bd29fb2" alt="Workflow Library" width="16" height="16" data-path="img/Icons/play-box.svg" />

    Preview this Workflow on desktop
  </div>

  <iframe className="iframe" src="https://library.blinkops.com/workflows/create-rules-with-proofpoint-itm-and-send-results-via-email/canvas" />
</div>
