Duplicate an exception list
Spaces method and path for this operation:
<div><span class="operation-verb post">post</span> <span class="operation-path">/s/{space_id}/api/exception_lists/_duplicate</span></div>Refer to Spaces for more information.
Duplicate an existing exception list.
Query parameters
The exception list's human-readable string identifier.
For endpoint artifacts, use one of the following values:
- endpoint_list: Elastic Endpoint exceptions list
- endpoint_trusted_apps: Trusted applications list
- endpoint_trusted_devices: Trusted devices list
- endpoint_event_filters: Event filters list
- endpoint_host_isolation_exceptions: Host isolation exceptions list
- endpoint_blocklists: Blocklist
The list_id of the existing exception list to copy (source list).
Determines whether the exception container is available in all Kibana spaces or just the space in which it is created, where:
- single: Only available in the Kibana space in which it is created.
- agnostic: Available in all Kibana spaces.
For endpoint artifacts, the namespace_type must always be agnostic. Space awareness for endpoint artifacts is enforced based on Elastic Defend policy assignments.
Scope in which the source list is defined (single = current space, agnostic = all spaces).
Determines whether to include expired exceptions in the duplicated list. Expiration date defined by expire_time.
Response
Successful response
Example response
{
"description": "This list tracks allowlisted values.",
"id": "9e5fc75a-a3da-46c5-96e3-a2ec59c6bb85",
"list_id": "simple_list",
"name": "My exception list"
}