openapi: 3.2.0 info: contact: name: Kibana Team description: 'The Kibana REST APIs enable you to manage resources such as connectors, data views, and saved objects. The API calls are stateless. Each request that you make happens in isolation from other calls and must include all of the necessary information for Kibana to fulfill the request. API requests return JSON output, which is a format that is machine-readable and works well for automation. To interact with Kibana APIs, use the following operations: - GET: Fetches the information. - PATCH: Applies partial modifications to the existing information. - POST: Adds new information. - PUT: Updates the existing information. - DELETE: Removes the information. You can prepend any Kibana API endpoint with `kbn:` and run the request in **Dev Tools → Console**. For example: ``` GET kbn:/api/data_views ``` For more information about the console, refer to [Run API requests](https://www.elastic.co/docs/explore-analyze/query-filter/tools/console). NOTE: Access to internal Kibana API endpoints will be restricted in Kibana version 9.0. Please move any integrations to publicly documented APIs. ## Documentation source and versions This documentation is derived from the `main` branch of the [kibana](https://github.com/elastic/kibana) repository. It is provided under license [Attribution-NonCommercial-NoDerivatives 4.0 International](https://creativecommons.org/licenses/by-nc-nd/4.0/). This documentation contains work-in-progress information for future Elastic Stack releases. ' title: Kibana Alerting API version: '' x-doc-license: name: Attribution-NonCommercial-NoDerivatives 4.0 International url: https://creativecommons.org/licenses/by-nc-nd/4.0/ x-feedbackLink: label: Feedback url: https://github.com/elastic/docs-content/issues/new?assignees=&labels=feedback%2Ccommunity&projects=&template=api-feedback.yaml&title=%5BFeedback%5D%3A+ servers: - url: https://{kibana_url} variables: kibana_url: default: localhost:5601 security: - apiKeyAuth: [] - basicAuth: [] tags: - name: alerting description: 'Alerting enables you to define rules, which detect complex conditions within your data. When a condition is met, the rule tracks it as an alert and runs the actions that are defined in the rule. Actions typically involve the use of connectors to interact with Kibana services or third party integrations. ' externalDocs: description: Alerting documentation url: https://www.elastic.co/docs/explore-analyze/alerts-cases/alerts x-displayName: Alerting paths: /api/alerting/_health: get: description: '**Spaces method and path for this operation:**
get /s/{space_id}/api/alerting/_health
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. You must have `read` privileges for the **Management > Stack Rules** feature or for at least one of the **Analytics > Discover**, **Analytics > Machine Learning**, **Observability**, or **Security** features. ' operationId: getAlertingHealth responses: '200': content: application/json: examples: getAlertingHealthResponse: $ref: '#/components/examples/Alerting_get_health_response' schema: type: object properties: alerting_framework_health: description: 'Three substates identify the health of the alerting framework: `decryption_health`, `execution_health`, and `read_health`. ' type: object properties: decryption_health: description: The timestamp and status of the rule decryption. type: object properties: status: enum: - error - ok - warn example: ok type: string timestamp: example: '2023-01-13T01:28:00.280Z' format: date-time type: string execution_health: description: The timestamp and status of the rule run. type: object properties: status: enum: - error - ok - warn example: ok type: string timestamp: example: '2023-01-13T01:28:00.280Z' format: date-time type: string read_health: description: The timestamp and status of the rule reading events. type: object properties: status: enum: - error - ok - warn example: ok type: string timestamp: example: '2023-01-13T01:28:00.280Z' format: date-time type: string has_permanent_encryption_key: description: If `false`, the encrypted saved object plugin does not have a permanent encryption key. example: true type: boolean is_sufficiently_secure: description: If `false`, security is enabled but TLS is not. example: true type: boolean description: Indicates a successful call. '401': content: application/json: examples: healthUnauthorizedResponse: $ref: '#/components/examples/Alerting_401_health_response' schema: $ref: '#/components/schemas/Alerting_401_response' description: Authorization information is missing or invalid. summary: Get the alerting framework health tags: - alerting x-metaTags: - content: Kibana name: product_name /api/alerting/rule_types: get: description: '**Spaces method and path for this operation:**
get /s/{space_id}/api/alerting/rule_types
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. If you have `read` privileges for one or more Kibana features, the API response contains information about the appropriate rule types. For example, there are rule types associated with the **Management > Stack Rules** feature, **Analytics > Discover** and **Machine Learning** features, **Observability** features, and **Security** features. To get rule types associated with the **Stack Monitoring** feature, use the `monitoring_user` built-in role. ' operationId: getRuleTypes responses: '200': content: application/json: examples: getRuleTypesResponse: $ref: '#/components/examples/Alerting_get_rule_types_response' schema: items: type: object properties: action_groups: description: 'An explicit list of groups for which the rule type can schedule actions, each with the action group''s unique ID and human readable name. Rule actions validation uses this configuration to ensure that groups are valid. ' items: type: object properties: id: type: string name: type: string type: array action_variables: description: 'A list of action variables that the rule type makes available via context and state in action parameter templates, and a short human readable description. When you create a rule in Kibana, it uses this information to prompt you for these variables in action parameter editors. ' type: object properties: context: items: type: object properties: description: type: string name: type: string useWithTripleBracesInTemplates: type: boolean type: array params: items: type: object properties: description: type: string name: type: string type: array state: items: type: object properties: description: type: string name: type: string type: array alerts: description: 'Details for writing alerts as data documents for this rule type. ' type: object properties: context: description: 'The namespace for this rule type. ' enum: - ml.anomaly-detection - observability.apm - observability.logs - observability.metrics - observability.slo - observability.threshold - observability.uptime - security - stack type: string dynamic: description: Indicates whether new fields are added dynamically. enum: - 'false' - runtime - strict - 'true' type: string isSpaceAware: description: 'Indicates whether the alerts are space-aware. If true, space-specific alert indices are used. ' type: boolean mappings: type: object properties: fieldMap: additionalProperties: $ref: '#/components/schemas/Alerting_fieldmap_properties' description: 'Mapping information for each field supported in alerts as data documents for this rule type. For more information about mapping parameters, refer to the Elasticsearch documentation. ' type: object secondaryAlias: description: 'A secondary alias. It is typically used to support the signals alias for detection rules. ' type: string shouldWrite: description: 'Indicates whether the rule should write out alerts as data. ' type: boolean useEcs: description: 'Indicates whether to include the ECS component template for the alerts. ' type: boolean useLegacyAlerts: default: false description: 'Indicates whether to include the legacy component template for the alerts. ' type: boolean authorized_consumers: description: The list of the plugins IDs that have access to the rule type. type: object properties: alerts: type: object properties: all: type: boolean read: type: boolean apm: type: object properties: all: type: boolean read: type: boolean discover: type: object properties: all: type: boolean read: type: boolean infrastructure: type: object properties: all: type: boolean read: type: boolean logs: type: object properties: all: type: boolean read: type: boolean ml: type: object properties: all: type: boolean read: type: boolean monitoring: type: object properties: all: type: boolean read: type: boolean siem: type: object properties: all: type: boolean read: type: boolean slo: type: object properties: all: type: boolean read: type: boolean stackAlerts: type: object properties: all: type: boolean read: type: boolean uptime: type: object properties: all: type: boolean read: type: boolean category: description: The rule category, which is used by features such as category-specific maintenance windows. enum: - management - observability - securitySolution type: string default_action_group_id: description: The default identifier for the rule type group. type: string does_set_recovery_context: description: Indicates whether the rule passes context variables to its recovery action. type: boolean enabled_in_license: description: Indicates whether the rule type is enabled or disabled based on the subscription. type: boolean has_alerts_mappings: description: Indicates whether the rule type has custom mappings for the alert data. type: boolean has_fields_for_a_a_d: type: boolean id: description: The unique identifier for the rule type. type: string is_exportable: description: Indicates whether the rule type is exportable in **Stack Management > Saved Objects**. type: boolean minimum_license_required: description: The subscriptions required to use the rule type. example: basic type: string name: description: The descriptive name of the rule type. type: string producer: description: An identifier for the application that produces this rule type. example: stackAlerts type: string recovery_action_group: description: An action group to use when an alert goes from an active state to an inactive one. type: object properties: id: type: string name: type: string rule_task_timeout: example: 5m type: string type: array description: Indicates a successful call. '401': content: application/json: examples: ruleTypesUnauthorizedResponse: $ref: '#/components/examples/Alerting_401_rule_types_response' schema: $ref: '#/components/schemas/Alerting_401_response' description: Authorization information is missing or invalid. summary: Get the rule types tags: - alerting x-metaTags: - content: Kibana name: product_name /api/alerting/rule/{id}: delete: operationId: delete-alerting-rule-id parameters: - description: A required header to protect against CSRF attacks in: header name: kbn-xsrf required: true schema: example: 'true' type: string - description: The identifier for the rule. in: path name: id required: true schema: type: string responses: '204': description: Indicates a successful call. '400': description: Indicates an invalid schema or parameters. '403': description: Indicates that this call is forbidden. '404': description: Indicates a rule with the given ID does not exist. summary: Delete a rule tags: - alerting x-metaTags: - content: Kibana name: product_name description: '**Spaces method and path for this operation:**
delete /s/{space_id}/api/alerting/rule/{id}
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information.' get: operationId: get-alerting-rule-id parameters: - description: The identifier for the rule. in: path name: id required: true schema: type: string responses: '200': content: application/json: examples: getRuleResponse: description: A response that contains information about an index threshold rule. summary: Get an index threshold rule value: actions: [] api_key_owner: elastic consumer: alerts created_at: '2022-12-05T23:40:33.132Z' created_by: elastic enabled: true id: 3583a470-74f6-11ed-9801-35303b735aef mute_all: false muted_alert_ids: [] name: my alert notify_when: onActionGroupChange params: aggField: sheet.version aggType: avg groupBy: top index: - test-index termField: name.keyword termSize: 6 threshold: - 1000 thresholdComparator: '>' timeField: '@timestamp' timeWindowSize: 5 timeWindowUnit: m revision: 0 rule_type_id: .index-threshold schedule: interval: 1m tags: - cpu throttle: null updated_at: '2022-12-05T23:40:33.132Z' updated_by: elastic schema: $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_response' description: Indicates a successful call. '400': description: Indicates an invalid schema or parameters. '403': description: Indicates that this call is forbidden. '404': description: Indicates a rule with the given ID does not exist. summary: Get rule details tags: - alerting x-metaTags: - content: Kibana name: product_name description: '**Spaces method and path for this operation:**
get /s/{space_id}/api/alerting/rule/{id}
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information.' post: operationId: post-alerting-rule-id parameters: - description: A required header to protect against CSRF attacks in: header name: kbn-xsrf required: true schema: example: 'true' type: string - description: The identifier for the rule. If it is omitted, an ID is randomly generated. in: path name: id required: true schema: type: string requestBody: content: application/json: examples: createEsQueryEsqlRuleRequest: description: 'Create an Elasticsearch query rule that uses Elasticsearch Query Language (ES|QL) to define its query and a server log connector to send notifications. ' summary: Elasticsearch query rule (ES|QL) value: actions: - frequency: notify_when: onActiveAlert summary: false group: query matched id: d0db1fe0-78d6-11ee-9177-f7d404c8c945 params: level: info message: 'Elasticsearch query rule ''{{rule.name}}'' is active: - Value: {{context.value}} - Conditions Met: {{context.conditions}} over {{rule.params.timeWindowSize}}{{rule.params.timeWindowUnit}} - Timestamp: {{context.date}} - Link: {{context.link}}' consumer: stackAlerts name: my Elasticsearch query ESQL rule params: esqlQuery: esql: FROM kibana_sample_data_logs | KEEP bytes, clientip, host, geo.dest | where geo.dest != "GB" | STATS sumbytes = sum(bytes) by clientip, host | WHERE sumbytes > 5000 | SORT sumbytes desc | LIMIT 10 searchType: esqlQuery size: 0 threshold: - 0 thresholdComparator: '>' timeField: '@timestamp' timeWindowSize: 1 timeWindowUnit: d rule_type_id: .es-query schedule: interval: 1d createEsQueryKqlRuleRequest: description: Create an Elasticsearch query rule that uses Kibana query language (KQL). summary: Elasticsearch query rule (KQL) value: consumer: alerts name: my Elasticsearch query KQL rule params: aggType: count excludeHitsFromPreviousRun: true groupBy: all searchConfiguration: index: 90943e30-9a47-11e8-b64d-95841ca0b247 query: language: kuery query: '""geo.src : "US" ""' searchType: searchSource size: 100 threshold: - 1000 thresholdComparator: '>' timeWindowSize: 5 timeWindowUnit: m rule_type_id: .es-query schedule: interval: 1m createEsQueryRuleRequest: description: 'Create an Elasticsearch query rule that uses Elasticsearch query domain specific language (DSL) to define its query and a server log connector to send notifications. ' summary: Elasticsearch query rule (DSL) value: actions: - frequency: notify_when: onThrottleInterval summary: true throttle: 1d group: query matched id: fdbece50-406c-11ee-850e-c71febc4ca7f params: level: info message: The system has detected {{alerts.new.count}} new, {{alerts.ongoing.count}} ongoing, and {{alerts.recovered.count}} recovered alerts. - frequency: notify_when: onActionGroupChange summary: false group: recovered id: fdbece50-406c-11ee-850e-c71febc4ca7f params: level: info message: Recovered consumer: alerts name: my Elasticsearch query rule params: esQuery: '"""{"query":{"match_all" : {}}}"""' index: - kibana_sample_data_logs size: 100 threshold: - 100 thresholdComparator: '>' timeField: '@timestamp' timeWindowSize: 1 timeWindowUnit: d rule_type_id: .es-query schedule: interval: 1d createIndexThresholdRuleRequest: description: 'Create an index threshold rule that uses a server log connector to send notifications when the threshold is met. ' summary: Index threshold rule value: actions: - frequency: notify_when: onActionGroupChange summary: false group: threshold met id: 48de3460-f401-11ed-9f8e-399c75a2deeb params: level: info message: 'Rule ''{{rule.name}}'' is active for group ''{{context.group}}'': - Value: {{context.value}} - Conditions Met: {{context.conditions}} over {{rule.params.timeWindowSize}}{{rule.params.timeWindowUnit}} - Timestamp: {{context.date}}' alert_delay: active: 3 consumer: alerts name: my rule params: aggField: sheet.version aggType: avg groupBy: top index: - .test-index termField: name.keyword termSize: 6 threshold: - 1000 thresholdComparator: '>' timeField: '@timestamp' timeWindowSize: 5 timeWindowUnit: m rule_type_id: .index-threshold schedule: interval: 1m tags: - cpu createTrackingContainmentRuleRequest: description: 'Create a tracking containment rule that checks when an entity is contained or no longer contained within a boundary. ' summary: Tracking containment rule value: consumer: alerts name: my tracking rule params: boundaryGeoField: location boundaryIndexId: 0cd90abf-abe7-44c7-909a-f621bbbcfefc boundaryIndexTitle: boundary* boundaryNameField: name boundaryType: entireIndex dateField": '@timestamp' entity: agent.keyword geoField: geo.coordinates index: kibana_sample_data_logs indexId: 90943e30-9a47-11e8-b64d-95841ca0b247 rule_type_id: .geo-containment schedule: interval: 1h schema: anyOf: - discriminator: mapping: .es-query: '#/components/schemas/Kibana_HTTP_APIs_es-query-create-rule-body-alerting' .geo-containment: '#/components/schemas/Kibana_HTTP_APIs_geo-containment-create-rule-body-alerting' .index-threshold: '#/components/schemas/Kibana_HTTP_APIs_index-threshold-create-rule-body-alerting' apm.anomaly: '#/components/schemas/Kibana_HTTP_APIs_apm-anomaly-create-rule-body-alerting' apm.error_rate: '#/components/schemas/Kibana_HTTP_APIs_apm-error-rate-create-rule-body-alerting' apm.transaction_duration: '#/components/schemas/Kibana_HTTP_APIs_apm-transaction-duration-create-rule-body-alerting' apm.transaction_error_rate: '#/components/schemas/Kibana_HTTP_APIs_apm-transaction-error-rate-create-rule-body-alerting' datasetQuality.degradedDocs: '#/components/schemas/Kibana_HTTP_APIs_datasetquality-degradeddocs-create-rule-body-alerting' logs.alert.document.count: '#/components/schemas/Kibana_HTTP_APIs_logs-alert-document-count-create-rule-body-alerting' metrics.alert.inventory.threshold: '#/components/schemas/Kibana_HTTP_APIs_metrics-alert-inventory-threshold-create-rule-body-alerting' metrics.alert.threshold: '#/components/schemas/Kibana_HTTP_APIs_metrics-alert-threshold-create-rule-body-alerting' monitoring_alert_cluster_health: '#/components/schemas/Kibana_HTTP_APIs_monitoring-alert-cluster-health-create-rule-body-alerting' monitoring_alert_cpu_usage: '#/components/schemas/Kibana_HTTP_APIs_monitoring-alert-cpu-usage-create-rule-body-alerting' monitoring_alert_disk_usage: '#/components/schemas/Kibana_HTTP_APIs_monitoring-alert-disk-usage-create-rule-body-alerting' monitoring_alert_elasticsearch_version_mismatch: '#/components/schemas/Kibana_HTTP_APIs_monitoring-alert-elasticsearch-version-mismatch-create-rule-body-alerting' monitoring_alert_jvm_memory_usage: '#/components/schemas/Kibana_HTTP_APIs_monitoring-alert-jvm-memory-usage-create-rule-body-alerting' monitoring_alert_kibana_version_mismatch: '#/components/schemas/Kibana_HTTP_APIs_monitoring-alert-kibana-version-mismatch-create-rule-body-alerting' monitoring_alert_license_expiration: '#/components/schemas/Kibana_HTTP_APIs_monitoring-alert-license-expiration-create-rule-body-alerting' monitoring_alert_logstash_version_mismatch: '#/components/schemas/Kibana_HTTP_APIs_monitoring-alert-logstash-version-mismatch-create-rule-body-alerting' monitoring_alert_missing_monitoring_data: '#/components/schemas/Kibana_HTTP_APIs_monitoring-alert-missing-monitoring-data-create-rule-body-alerting' monitoring_alert_nodes_changed: '#/components/schemas/Kibana_HTTP_APIs_monitoring-alert-nodes-changed-create-rule-body-alerting' monitoring_alert_thread_pool_search_rejections: '#/components/schemas/Kibana_HTTP_APIs_monitoring-alert-thread-pool-search-rejections-create-rule-body-alerting' monitoring_alert_thread_pool_write_rejections: '#/components/schemas/Kibana_HTTP_APIs_monitoring-alert-thread-pool-write-rejections-create-rule-body-alerting' monitoring_ccr_read_exceptions: '#/components/schemas/Kibana_HTTP_APIs_monitoring-ccr-read-exceptions-create-rule-body-alerting' monitoring_shard_size: '#/components/schemas/Kibana_HTTP_APIs_monitoring-shard-size-create-rule-body-alerting' observability.rules.custom_threshold: '#/components/schemas/Kibana_HTTP_APIs_observability-rules-custom-threshold-create-rule-body-alerting' slo.rules.burnRate: '#/components/schemas/Kibana_HTTP_APIs_slo-rules-burnrate-create-rule-body-alerting' transform_health: '#/components/schemas/Kibana_HTTP_APIs_transform-health-create-rule-body-alerting' xpack.ml.anomaly_detection_alert: '#/components/schemas/Kibana_HTTP_APIs_xpack-ml-anomaly-detection-alert-create-rule-body-alerting' xpack.ml.anomaly_detection_jobs_health: '#/components/schemas/Kibana_HTTP_APIs_xpack-ml-anomaly-detection-jobs-health-create-rule-body-alerting' xpack.synthetics.alerts.monitorStatus: '#/components/schemas/Kibana_HTTP_APIs_xpack-synthetics-alerts-monitorstatus-create-rule-body-alerting' xpack.synthetics.alerts.tls: '#/components/schemas/Kibana_HTTP_APIs_xpack-synthetics-alerts-tls-create-rule-body-alerting' xpack.uptime.alerts.durationAnomaly: '#/components/schemas/Kibana_HTTP_APIs_xpack-uptime-alerts-durationanomaly-create-rule-body-alerting' xpack.uptime.alerts.monitorStatus: '#/components/schemas/Kibana_HTTP_APIs_xpack-uptime-alerts-monitorstatus-create-rule-body-alerting' xpack.uptime.alerts.tlsCertificate: '#/components/schemas/Kibana_HTTP_APIs_xpack-uptime-alerts-tlscertificate-create-rule-body-alerting' propertyName: rule_type_id oneOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_monitoring-ccr-read-exceptions-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_monitoring-alert-cluster-health-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_monitoring-alert-cpu-usage-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_monitoring-alert-disk-usage-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_monitoring-alert-elasticsearch-version-mismatch-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_monitoring-alert-kibana-version-mismatch-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_monitoring-alert-license-expiration-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_monitoring-alert-logstash-version-mismatch-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_monitoring-alert-jvm-memory-usage-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_monitoring-alert-missing-monitoring-data-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_monitoring-alert-nodes-changed-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_monitoring-shard-size-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_monitoring-alert-thread-pool-search-rejections-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_monitoring-alert-thread-pool-write-rejections-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_xpack-ml-anomaly-detection-alert-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_xpack-ml-anomaly-detection-jobs-health-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_datasetquality-degradeddocs-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_es-query-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_index-threshold-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_geo-containment-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_transform-health-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_apm-anomaly-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_apm-error-rate-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_apm-transaction-error-rate-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_apm-transaction-duration-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_xpack-synthetics-alerts-monitorstatus-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_xpack-synthetics-alerts-tls-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_xpack-uptime-alerts-monitorstatus-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_xpack-uptime-alerts-tlscertificate-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_xpack-uptime-alerts-durationanomaly-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_metrics-alert-inventory-threshold-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_metrics-alert-threshold-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_observability-rules-custom-threshold-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_logs-alert-document-count-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_slo-rules-burnrate-create-rule-body-alerting' - $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule' responses: '200': content: application/json: examples: createEsQueryEsqlRuleResponse: description: The response for successfully creating an Elasticsearch query rule that uses Elasticsearch Query Language (ES|QL). summary: Elasticsearch query rule (ES|QL) value: actions: - connector_type_id: .server-log frequency: notify_when: onActiveAlert summary: false throttle: null group: query matched id: d0db1fe0-78d6-11ee-9177-f7d404c8c945 params: level: info message: 'Elasticsearch query rule ''{{rule.name}}'' is active: - Value: {{context.value}} - Conditions Met: {{context.conditions}} over {{rule.params.timeWindowSize}}{{rule.params.timeWindowUnit}} - Timestamp: {{context.date}} - Link: {{context.link}}' uuid: bfe370a3-531b-4855-bbe6-ad739f578844 api_key_created_by_user: false api_key_owner: elastic consumer: stackAlerts created_at: '2023-11-01T19:00:10.453Z' created_by: elastic enabled: true execution_status: last_execution_date: '2023-11-01T19:00:10.453Z' status: pending id: e0d62360-78e8-11ee-9177-f7d404c8c945 mute_all: false muted_alert_ids: [] name: my Elasticsearch query ESQL rule notify_when: null params: aggType: count esqlQuery: esql: FROM kibana_sample_data_logs | keep bytes, clientip, host, geo.dest | WHERE geo.dest != "GB" | stats sumbytes = sum(bytes) by clientip, host | WHERE sumbytes > 5000 | sort sumbytes desc | limit 10 excludeHitsFromPreviousRun": true, groupBy: all searchType: esqlQuery size: 0 threshold: - 0 thresholdComparator: '>' timeField: '@timestamp' timeWindowSize: 1 timeWindowUnit: d revision: 0 rule_type_id: .es-query running: false schedule: interval: 1d scheduled_task_id: e0d62360-78e8-11ee-9177-f7d404c8c945 tags: [] throttle: null updated_at: '2023-11-01T19:00:10.453Z' updated_by: elastic", createEsQueryKqlRuleResponse: description: The response for successfully creating an Elasticsearch query rule that uses Kibana query language (KQL). summary: Elasticsearch query rule (KQL) value: actions: [] api_key_created_by_user: false api_key_owner: elastic consumer: alerts created_at: '2023-07-14T20:24:50.729Z' created_by: elastic enabled: true execution_status: last_execution_date: '2023-07-14T20:24:50.729Z' status: pending id: 7bd506d0-2284-11ee-8fad-6101956ced88 mute_all: false muted_alert_ids: [] name: my Elasticsearch query KQL rule" notify_when: null params: aggType: count excludeHitsFromPreviousRun: true groupBy: all searchConfiguration: index: 90943e30-9a47-11e8-b64d-95841ca0b247 query: language: kuery query: '""geo.src : "US" ""' searchType: searchSource size: 100 threshold: - 1000 thresholdComparator: '>' timeWindowSize: 5 timeWindowUnit: m revision: 0 rule_type_id: .es-query running: false schedule: interval: 1m scheduled_task_id: 7bd506d0-2284-11ee-8fad-6101956ced88 tags: [] throttle: null updated_at: '2023-07-14T20:24:50.729Z' updated_by: elastic createEsQueryRuleResponse: description: The response for successfully creating an Elasticsearch query rule that uses Elasticsearch query domain specific language (DSL). summary: Elasticsearch query rule (DSL) value: actions: - connector_type_id: .server-log frequency: notify_when: onThrottleInterval summary: true throttle: 1d group: query matched id: fdbece50-406c-11ee-850e-c71febc4ca7f params: level: info message: The system has detected {{alerts.new.count}} new, {{alerts.ongoing.count}} ongoing, and {{alerts.recovered.count}} recovered alerts. uuid: 53f3c2a3-e5d0-4cfa-af3b-6f0881385e78 - connector_type_id: .server-log frequency: notify_when: onActionGroupChange summary: false throttle: null group: recovered id: fdbece50-406c-11ee-850e-c71febc4ca7f params: level: info message: Recovered uuid: 2324e45b-c0df-45c7-9d70-4993e30be758 api_key_created_by_user: false api_key_owner: elastic consumer: alerts created_at: '2023-08-22T00:03:38.263Z' created_by: elastic enabled: true execution_status: last_execution_date: '2023-08-22T00:03:38.263Z' status: pending id: 58148c70-407f-11ee-850e-c71febc4ca7f mute_all: false muted_alert_ids: [] name: my Elasticsearch query rule notify_when: null params: aggType: count esQuery: '"""{"query":{"match_all" : {}}}"""' excludeHitsFromPreviousRun: true groupBy: all index: - kibana_sample_data_logs searchType: esQuery size: 100 threshold: - 100 thresholdComparator: '>' timeField: '@timestamp' timeWindowSize: 1 timeWindowUnit: d revision: 0 rule_type_id: .es-query running: false schedule: interval: 1d scheduled_task_id: 58148c70-407f-11ee-850e-c71febc4ca7f tags: [] throttle: null updated_at: '2023-08-22T00:03:38.263Z' updated_by: elastic createIndexThresholdRuleResponse: description: The response for successfully creating an index threshold rule. summary: Index threshold rule value: actions: - connector_type_id: .server-log frequency: notify_when: onActionGroupChange summary: false throttle: null group: threshold met id: dceeb5d0-6b41-11eb-802b-85b0c1bc8ba2 params: level: info message: 'Rule {{rule.name}} is active for group {{context.group} : - Value: {{context.value}} - Conditions Met: {{context.conditions}} over {{rule.params.timeWindowSize}}{{rule.params.timeWindowUnit}} - Timestamp: {{context.date}}' uuid: 07aef2a0-9eed-4ef9-94ec-39ba58eb609d alert_delay: active: 3 api_key_created_by_user: false api_key_owner: elastic consumer: alerts created_at: '2022-06-08T17:20:31.632Z' created_by: elastic enabled: true execution_status: last_execution_date: '2022-06-08T17:20:31.632Z' status: pending id: 41893910-6bca-11eb-9e0d-85d233e3ee35 mute_all: false muted_alert_ids: [] name: my rule notify_when: null params: aggField: sheet.version aggType: avg groupBy: top index: - .test-index termField: name.keyword termSize: 6 threshold: - 1000 thresholdComparator: '>' timeField: '@timestamp' timeWindowSize: 5 timeWindowUnit: m revision: 0 rule_type_id: .index-threshold running: false schedule: interval: 1m scheduled_task_id: 425b0800-6bca-11eb-9e0d-85d233e3ee35 tags: - cpu throttle: null updated_at: '2022-06-08T17:20:31.632Z' updated_by: elastic createTrackingContainmentRuleResponse: description: The response for successfully creating a tracking containment rule. summary: Tracking containment rule value: actions: [] api_key_created_by_user: false api_key_owner: elastic consumer: alerts created_at: '2024-02-14T19:52:55.920Z' created_by: elastic enabled: true execution_status: last_duration: 74 last_execution_date: '2024-02-15T03:25:38.125Z' status: ok id: b6883f9d-5f70-4758-a66e-369d7c26012f last_run: alerts_count: active: 0 ignored: 0 new: 0 recovered: 0 outcome: succeeded outcome_msg: null outcome_order: 0 warning: null mute_all: false muted_alert_ids: [] name: my tracking rule next_run: '2024-02-15T03:26:38.033Z' notify_when: null params: boundaryGeoField: location boundaryIndexId: 0cd90abf-abe7-44c7-909a-f621bbbcfefc boundaryIndexTitle: boundary* boundaryNameField: name boundaryType: entireIndex dateField: '@timestamp' entity: agent.keyword geoField: geo.coordinates index: kibana_sample_data_logs indexId: 90943e30-9a47-11e8-b64d-95841ca0b247 revision: 1 rule_type_id: .geo-containment running: false schedule: interval: 1h scheduled_task_id: b6883f9d-5f70-4758-a66e-369d7c26012f tags: [] throttle: null updated_at: '2024-02-15T03:24:32.574Z' updated_by: elastic schema: $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_response' description: Indicates a successful call. '400': description: Indicates an invalid schema or parameters. '403': description: Indicates that this call is forbidden. '409': description: Indicates that the rule id is already in use. summary: Create a rule tags: - alerting x-metaTags: - content: Kibana name: product_name description: '**Spaces method and path for this operation:**
post /s/{space_id}/api/alerting/rule/{id}
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information.' put: operationId: put-alerting-rule-id parameters: - description: A required header to protect against CSRF attacks in: header name: kbn-xsrf required: true schema: example: 'true' type: string - description: The identifier for the rule. in: path name: id required: true schema: type: string requestBody: content: application/json: examples: updateRuleRequest: description: Update an index threshold rule that uses a server log connector to send notifications when the threshold is met. summary: Index threshold rule value: actions: - frequency: notify_when: onActionGroupChange summary: false group: threshold met id: 96b668d0-a1b6-11ed-afdf-d39a49596974 params: level: info message: 'Rule {{rule.name}} is active for group {{context.group}}: - Value: {{context.value}} - Conditions Met: {{context.conditions}} over {{rule.params.timeWindowSize}}{{rule.params.timeWindowUnit}} - Timestamp: {{context.date}}' name: new name params: aggField: sheet.version aggType: avg groupBy: top index: - .updated-index termField: name.keyword termSize: 6 threshold: - 1000 thresholdComparator: '>' timeField: '@timestamp' timeWindowSize: 5 timeWindowUnit: m schedule: interval: 1m tags: [] schema: $ref: '#/components/schemas/Kibana_HTTP_APIs_update_rule' responses: '200': content: application/json: examples: updateRuleResponse: description: The response for successfully updating an index threshold rule. summary: Index threshold rule value: actions: - connector_type_id: .server-log frequency: notify_when: onActionGroupChange summary: false throttle: null group: threshold met id: 96b668d0-a1b6-11ed-afdf-d39a49596974 params: level: info message: 'Rule {{rule.name}} is active for group {{context.group}}: - Value: {{context.value}} - Conditions Met: {{context.conditions}} over {{rule.params.timeWindowSize}}{{rule.params.timeWindowUnit}} - Timestamp: {{context.date}' uuid: 07aef2a0-9eed-4ef9-94ec-39ba58eb609d api_key_created_by_user: false api_key_owner: elastic consumer: alerts created_at: '2024-03-26T23:13:20.985Z' created_by: elastic enabled: true execution_status: last_duration: 52 last_execution_date: '2024-03-26T23:22:51.390Z' status: ok id: ac4e6b90-6be7-11eb-ba0d-9b1c1f912d74 last_run: alerts_count: active: 0 ignored: 0 new: 0 recovered: 0 outcome: succeeded outcome_msg: null warning: null mute_all: false muted_alert_ids: [] name: new name next_run: '2024-03-26T23:23:51.316Z' params: aggField: sheet.version aggType: avg groupBy: top index: - .updated-index termField: name.keyword termSize: 6 threshold: - 1000 thresholdComparator: '>' timeField: '@timestamp' timeWindowSize: 5 timeWindowUnit: m revision: 1 rule_type_id: .index-threshold running: false schedule: interval: 1m scheduled_task_id: 4c5eda00-e74f-11ec-b72f-5b18752ff9ea tags: [] throttle: null updated_at: '2024-03-26T23:22:59.949Z' updated_by: elastic schema: $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_response' description: Indicates a successful call. '400': description: Indicates an invalid schema or parameters. '403': description: Indicates that this call is forbidden. '404': description: Indicates a rule with the given ID does not exist. '409': description: Indicates that the rule has already been updated by another user. summary: Update a rule tags: - alerting x-metaTags: - content: Kibana name: product_name description: '**Spaces method and path for this operation:**
put /s/{space_id}/api/alerting/rule/{id}
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information.' /api/alerting/rule/{id}/_disable: post: operationId: post-alerting-rule-id-disable parameters: - description: A required header to protect against CSRF attacks in: header name: kbn-xsrf required: true schema: example: 'true' type: string - description: The identifier for the rule. in: path name: id required: true schema: type: string requestBody: content: application/json: examples: disableRuleRequest: description: A request that disables a rule and untracks all alerts that were generated by the rule. summary: Disable a rule and untrack its alerts value: untrack: true schema: additionalProperties: false default: null type: - object - 'null' properties: untrack: description: Defines whether this rule's alerts should be untracked. type: boolean responses: '204': description: Indicates a successful call. '400': description: Indicates an invalid schema. '403': description: Indicates that this call is forbidden. '404': description: Indicates a rule with the given ID does not exist. summary: Disable a rule tags: - alerting x-metaTags: - content: Kibana name: product_name description: '**Spaces method and path for this operation:**
post /s/{space_id}/api/alerting/rule/{id}/_disable
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information.' /api/alerting/rule/{id}/_enable: post: operationId: post-alerting-rule-id-enable parameters: - description: A required header to protect against CSRF attacks in: header name: kbn-xsrf required: true schema: example: 'true' type: string - description: The identifier for the rule. in: path name: id required: true schema: type: string responses: '204': description: Indicates a successful call. '400': description: Indicates an invalid schema or parameters. '403': description: Indicates that this call is forbidden. '404': description: Indicates a rule with the given ID does not exist. summary: Enable a rule tags: - alerting x-metaTags: - content: Kibana name: product_name description: '**Spaces method and path for this operation:**
post /s/{space_id}/api/alerting/rule/{id}/_enable
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information.' /api/alerting/rule/{id}/_mute_all: post: operationId: post-alerting-rule-id-mute-all parameters: - description: A required header to protect against CSRF attacks in: header name: kbn-xsrf required: true schema: example: 'true' type: string - description: The identifier for the rule. in: path name: id required: true schema: type: string responses: '204': description: Indicates a successful call. '400': description: Indicates an invalid schema or parameters. '403': description: Indicates that this call is forbidden. '404': description: Indicates a rule with the given ID does not exist. summary: Mute all alerts tags: - alerting x-metaTags: - content: Kibana name: product_name description: '**Spaces method and path for this operation:**
post /s/{space_id}/api/alerting/rule/{id}/_mute_all
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information.' /api/alerting/rule/{id}/_unmute_all: post: operationId: post-alerting-rule-id-unmute-all parameters: - description: A required header to protect against CSRF attacks in: header name: kbn-xsrf required: true schema: example: 'true' type: string - description: The identifier for the rule. in: path name: id required: true schema: type: string responses: '204': description: Indicates a successful call. '400': description: Indicates an invalid schema or parameters. '403': description: Indicates that this call is forbidden. '404': description: Indicates a rule with the given ID does not exist. summary: Unmute all alerts tags: - alerting x-metaTags: - content: Kibana name: product_name description: '**Spaces method and path for this operation:**
post /s/{space_id}/api/alerting/rule/{id}/_unmute_all
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information.' /api/alerting/rule/{id}/_update_api_key: post: operationId: post-alerting-rule-id-update-api-key parameters: - description: A required header to protect against CSRF attacks in: header name: kbn-xsrf required: true schema: example: 'true' type: string - description: The identifier for the rule. in: path name: id required: true schema: type: string responses: '204': description: Indicates a successful call. '400': description: Indicates an invalid schema or parameters. '403': description: Indicates that this call is forbidden. '404': description: Indicates a rule with the given ID does not exist. '409': description: Indicates that the rule has already been updated by another user. summary: Update the API key for a rule tags: - alerting x-metaTags: - content: Kibana name: product_name description: '**Spaces method and path for this operation:**
post /s/{space_id}/api/alerting/rule/{id}/_update_api_key
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information.' /api/alerting/rule/{id}/query_inspector: get: description: '**Spaces method and path for this operation:**
get /s/{space_id}/api/alerting/rule/{id}/query_inspector
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. Returns the Elasticsearch query that a rule executes, and optionally its response.' operationId: get-alerting-rule-id-query-inspector parameters: - description: The identifier for the rule. in: path name: id required: true schema: type: string - description: The inspection mode. Use "build" to return only the query, or "execute" to run the query and include the response. in: query name: mode required: false schema: default: build enum: - build - execute type: string - description: The alert document ID. When provided, the query inspector uses the evaluation time range from the alert instead of the current time. in: query name: alert_id required: false schema: type: string responses: '200': content: application/json: examples: getRuleQueryInspectorResponse: summary: A query inspector response for a custom threshold rule value: queries: - index: metrics-* request: aggs: groupings: composite: size: 500 sources: [] query: bool: filter: - range: '@timestamp': gte: '2026-01-01T00:00:00.000Z' lte: '2026-01-01T00:05:00.000Z' size: 0 schema: additionalProperties: false type: object properties: queries: items: additionalProperties: false type: object properties: index: type: string label: type: string request: additionalProperties: {} type: object response: additionalProperties: {} type: object required: - index - request maxItems: 1000 type: array required: - queries description: Indicates a successful call. '400': description: Indicates the rule type is not supported or the request parameters are invalid. '404': description: Indicates a rule with the specified rule ID does not exist. summary: Get the Elasticsearch query for a rule tags: - alerting x-metaTags: - content: Kibana name: product_name /api/alerting/rule/{id}/snooze_schedule: post: description: '**Spaces method and path for this operation:**
post /s/{space_id}/api/alerting/rule/{id}/snooze_schedule
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information. When you snooze a rule, the rule checks continue to run but alerts will not generate actions. You can snooze for a specified period of time and schedule single or recurring downtimes.' operationId: post-alerting-rule-id-snooze-schedule parameters: - description: A required header to protect against CSRF attacks in: header name: kbn-xsrf required: true schema: example: 'true' type: string - description: Identifier of the rule. in: path name: id required: true schema: type: string requestBody: content: application/json: examples: snoozeRuleRecurringRequest: description: A request that snoozes a rule every Monday for 8 hours, for 4 occurrences. summary: Snooze a rule on a recurring weekly schedule value: schedule: custom: duration: 8h recurring: every: 1w occurrences: 4 onWeekDay: - MO start: '2025-03-17T09:00:00.000Z' timezone: UTC snoozeRuleRequest: description: A request that snoozes a rule for 24 hours starting now. summary: Snooze a rule for 24 hours value: schedule: custom: duration: 24h start: '2025-03-12T12:00:00.000Z' timezone: UTC schema: additionalProperties: false type: object properties: schedule: additionalProperties: false type: object properties: custom: $ref: '#/components/schemas/Kibana_HTTP_APIs_schedule_request' required: - schedule responses: '200': content: application/json: examples: snoozeRuleResponse: description: A response that contains the created snooze schedule. summary: Snooze schedule response value: schedule: custom: duration: 24h start: '2025-03-12T12:00:00.000Z' timezone: UTC id: 9ac67950-6737-11ec-8ded-d7f6e1581b26 schema: additionalProperties: false type: object properties: body: additionalProperties: false type: object properties: schedule: additionalProperties: false type: object properties: custom: $ref: '#/components/schemas/Kibana_HTTP_APIs_schedule_request' id: description: Identifier of the snooze schedule. type: string required: - id required: - schedule required: - body description: Indicates a successful call. '400': description: Indicates an invalid schema. '403': description: Indicates that this call is forbidden. '404': description: Indicates a rule with the given id does not exist. summary: Schedule a snooze for the rule tags: - alerting x-state: Generally available; added in 8.19.0 x-metaTags: - content: Kibana name: product_name /api/alerting/rule/{rule_id}/alert/{alert_id}/_mute: post: operationId: post-alerting-rule-rule-id-alert-alert-id-mute parameters: - description: A required header to protect against CSRF attacks in: header name: kbn-xsrf required: true schema: example: 'true' type: string - description: The identifier for the rule. in: path name: rule_id required: true schema: type: string - description: The identifier for the alert. in: path name: alert_id required: true schema: type: string - description: Whether to validate the existence of the alert. in: query name: validate_alerts_existence required: false schema: type: boolean responses: '204': description: Indicates a successful call. '400': description: Indicates an invalid schema or parameters. '403': description: Indicates that this call is forbidden. '404': description: Indicates a rule or alert with the given ID does not exist. summary: Mute an alert tags: - alerting x-metaTags: - content: Kibana name: product_name description: '**Spaces method and path for this operation:**
post /s/{space_id}/api/alerting/rule/{rule_id}/alert/{alert_id}/_mute
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information.' /api/alerting/rule/{rule_id}/alert/{alert_id}/_snooze: post: operationId: post-alerting-rule-rule-id-alert-alert-id-snooze parameters: - description: A required header to protect against CSRF attacks in: header name: kbn-xsrf required: true schema: example: 'true' type: string - description: The identifier for the rule. in: path name: rule_id required: true schema: maxLength: 256 type: string - description: The identifier for the alert. in: path name: alert_id required: true schema: maxLength: 1000 type: string - description: Set to `true` to validate that the specified alert exists. If a `400` error is returned, the specified alert does not exist. Defaults to `true`. in: query name: validate_alerts_existence required: false schema: type: boolean requestBody: content: application/json: schema: additionalProperties: false type: object properties: condition_operator: description: Logical operator applied to the conditions array. "any" expires the snooze when at least one condition is met; "all" requires every condition to be met. When conditions are provided but this field is omitted, defaults to "any". enum: - any - all type: string conditions: description: 'One or more conditions that, when met, automatically expire the snooze. Supported types: `field_change`, `severity_change`, `severity_equals`.' items: anyOf: - additionalProperties: false description: Expires the snooze when the value of the specified alert field changes. type: object properties: field: description: The alert field to watch, written as a dot-notation path. When the value of the specified alert field changes, the snooze expires maxLength: 1000 type: string type: enum: - field_change type: string required: - type - field - additionalProperties: false description: Expires the snooze when the severity of the specified alert changes. type: object properties: type: enum: - severity_change type: string required: - type - additionalProperties: false description: Expires the snooze when the severity of the specified alert equals a target level. type: object properties: type: enum: - severity_equals type: string value: description: 'The target severity level: critical, major, high, medium, minor, low, warning, or info.' enum: - critical - major - high - medium - minor - low - warning - info type: string required: - type - value maxItems: 10 type: array expires_at: description: The datetime at which the snooze expires, in ISO 8601 format (`YYYY-MM-DDTHH:mm:ss.sssZ`). When omitted, the snooze persists indefinitely unless manually removed or a defined condition is met. maxLength: 30 type: string responses: '204': description: Indicates a successful call. '400': description: Indicates an invalid schema or parameters. '403': description: Indicates that this call is forbidden. '404': description: Indicates the specified rule or alert doesn't exist. summary: Snooze an alert tags: - alerting x-state: Generally available; added in 9.5.0 x-metaTags: - content: Kibana name: product_name description: '**Spaces method and path for this operation:**
post /s/{space_id}/api/alerting/rule/{rule_id}/alert/{alert_id}/_snooze
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information.' /api/alerting/rule/{rule_id}/alert/{alert_id}/_unmute: post: operationId: post-alerting-rule-rule-id-alert-alert-id-unmute parameters: - description: A required header to protect against CSRF attacks in: header name: kbn-xsrf required: true schema: example: 'true' type: string - description: The identifier for the rule. in: path name: rule_id required: true schema: type: string - description: The identifier for the alert. in: path name: alert_id required: true schema: type: string responses: '204': description: Indicates a successful call. '400': description: Indicates an invalid schema or parameters. '403': description: Indicates that this call is forbidden. '404': description: Indicates a rule or alert with the given ID does not exist. summary: Unmute an alert tags: - alerting x-metaTags: - content: Kibana name: product_name description: '**Spaces method and path for this operation:**
post /s/{space_id}/api/alerting/rule/{rule_id}/alert/{alert_id}/_unmute
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information.' /api/alerting/rule/{rule_id}/alert/{alert_id}/_unsnooze: post: operationId: post-alerting-rule-rule-id-alert-alert-id-unsnooze parameters: - description: A required header to protect against CSRF attacks in: header name: kbn-xsrf required: true schema: example: 'true' type: string - description: The identifier for the rule. in: path name: rule_id required: true schema: maxLength: 256 type: string - description: The identifier for the alert. in: path name: alert_id required: true schema: maxLength: 1000 type: string responses: '204': description: Indicates a successful call. '400': description: Indicates an invalid schema or parameters. '403': description: Indicates that this call is forbidden. '404': description: Indicates the specified rule or alert doesn't exist. summary: Unsnooze an alert tags: - alerting x-state: Generally available; added in 9.5.0 x-metaTags: - content: Kibana name: product_name description: '**Spaces method and path for this operation:**
post /s/{space_id}/api/alerting/rule/{rule_id}/alert/{alert_id}/_unsnooze
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information.' /api/alerting/rule/{ruleId}/snooze_schedule/{scheduleId}: delete: operationId: delete-alerting-rule-ruleid-snooze-schedule-scheduleid parameters: - description: A required header to protect against CSRF attacks in: header name: kbn-xsrf required: true schema: example: 'true' type: string - description: The identifier for the rule. in: path name: ruleId required: true schema: type: string - description: The identifier for the snooze schedule. in: path name: scheduleId required: true schema: type: string responses: '204': description: Indicates a successful call. '400': description: Indicates an invalid schema. '403': description: Indicates that this call is forbidden. '404': description: Indicates a rule with the given id does not exist. summary: Delete a snooze schedule for a rule tags: - alerting x-state: Generally available; added in 8.19.0 x-metaTags: - content: Kibana name: product_name description: '**Spaces method and path for this operation:**
delete /s/{space_id}/api/alerting/rule/{ruleId}/snooze_schedule/{scheduleId}
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information.' /api/alerting/rules/_find: get: operationId: get-alerting-rules-find parameters: - description: The number of rules to return per page. in: query name: per_page required: false schema: default: 10 minimum: 0 type: number - description: The page number to return. in: query name: page required: false schema: default: 1 minimum: 1 type: number - description: An Elasticsearch simple_query_string query that filters the objects in the response. in: query name: search required: false schema: type: string - description: The default operator to use for the simple_query_string. in: query name: default_search_operator required: false schema: default: OR enum: - OR - AND type: string - description: The fields to perform the simple_query_string parsed query against. in: query name: search_fields required: false schema: items: type: string type: array - description: Determines which field is used to sort the results. The field must exist in the `attributes` key of the response. in: query name: sort_field required: false schema: type: string - description: Determines the sort order. in: query name: sort_order required: false schema: enum: - asc - desc type: string - description: Filters the rules that have a relation with the reference objects with a specific type and identifier. in: query name: has_reference required: false schema: additionalProperties: false type: - object - 'null' properties: id: type: string type: type: string required: - type - id - description: The fields to return in the `attributes` key of the response. in: query name: fields required: false schema: items: type: string type: array - description: 'A KQL string that you filter with an attribute from your saved object. It should look like `savedObjectType.attributes.title: "myTitle"`. However, if you used a direct attribute of a saved object, such as `updatedAt`, you must define your filter, for example, `savedObjectType.updatedAt > 2018-12-22`.' in: query name: filter required: false schema: type: string - description: 'Filters the returned rules by the consumer (Kibana application) that owns them, for example: `siem`, `apm`, `infrastructure`.' in: query name: filter_consumers required: false schema: items: description: List of consumers to filter. type: string type: array responses: '200': content: application/json: examples: findConditionalActionRulesResponse: description: A response that contains information about an index threshold rule. summary: Index threshold rule value: data: - actions: - frequency: notify_when: onActionGroupChange summary: false throttle: null group: threshold met id: 9dca3e00-74f5-11ed-9801-35303b735aef params: connector_type_id: .server-log level: info message: 'Rule {{rule.name}} is active for group {{context.group}}: - Value: {{context.value}} - Conditions Met: {{context.conditions}} over {{rule.params.timeWindowSize}}{{rule.params.timeWindowUnit}} - Timestamp: {{context.date}}' uuid: 1c7a1280-f28c-4e06-96b2-e4e5f05d1d61 api_key_created_by_user: false api_key_owner: elastic consumer: alerts created_at: '2022-12-05T23:40:33.132Z' created_by: elastic enabled: true execution_status: last_duration: 48 last_execution_date: '2022-12-06T01:44:23.983Z' status: ok id: 3583a470-74f6-11ed-9801-35303b735aef last_run: alerts_count: active: 0 ignored: 0 new: 0 recovered: 0 outcome: succeeded outcome_msg: null warning: null mute_all: false muted_alert_ids: [] name: my alert next_run: '2022-12-06T01:45:23.912Z' params: aggField: sheet.version aggType: avg groupBy: top index: - test-index termField: name.keyword termSize: 6 threshold: - 1000 thresholdComparator: '>' timeField: '@timestamp' timeWindowSize: 5 timeWindowUnit: m revision: 1 rule_type_id: .index-threshold schedule: interval: 1m scheduled_task_id: 3583a470-74f6-11ed-9801-35303b735aef tags: - cpu throttle: null updated_at: '2022-12-05T23:40:33.132Z' updated_by: elastic page: 1 per_page: 10 total: 1 findRulesResponse: description: A response that contains information about a security rule that has conditional actions. summary: Security rule value: data: - actions: - alerts_filter: query: filters: - $state: store: appState meta: alias: null disabled: false field: client.geo.region_iso_code index: c4bdca79-e69e-4d80-82a1-e5192c621bea key: client.geo.region_iso_code negate: false params: query: CA-QC type: phrase query: match_phrase: client.geo.region_iso_code: CA-QC kql: '' timeframe: days: - 7 hours: end: '17:00' start: 08:00 timezone: UTC connector_type_id: .index frequency: notify_when: onActiveAlert summary: true throttle: null group: default id: 49eae970-f401-11ed-9f8e-399c75a2deeb params: documents: - alert_id: '[object Object]': null context_message: '[object Object]': null rule_id: '[object Object]': null rule_name: '[object Object]': null uuid: 1c7a1280-f28c-4e06-96b2-e4e5f05d1d61 api_key_created_by_user: false api_key_owner: elastic consumer: siem created_at: '2023-05-16T15:50:28.358Z' created_by: elastic enabled: true execution_status: last_duration: 166 last_execution_date: '2023-05-16T20:26:49.590Z' status: ok id: 6107a8f0-f401-11ed-9f8e-399c75a2deeb last_run: alerts_count: active: 0 ignored: 0 new: 0 recovered: 0 outcome: succeeded outcome_msg: - Rule execution completed successfully outcome_order: 0 warning: null mute_all: false muted_alert_ids: [] name: security_rule next_run: '2023-05-16T20:27:49.507Z' notify_when: null params: author: [] description: A security threshold rule. exceptionsList: [] falsePositives: [] filters: [] from: now-3660s immutable: false index: - kibana_sample_data_logs language: kuery license: '' maxSignals: 100 meta: from: 1h kibana_siem_app_url: https://localhost:5601/app/security outputIndex: '' query: '*' references: [] riskScore: 21 riskScoreMapping: [] ruleId: an_internal_rule_id severity: low severityMapping: [] threat: [] threshold: cardinality: [] field: - bytes value: 1 to: now type: threshold version: 1 revision: 1 rule_type_id: siem.thresholdRule running: false schedule: interval: 1m scheduled_task_id: 6107a8f0-f401-11ed-9f8e-399c75a2deeb tags: [] throttle: null updated_at: '2023-05-16T20:25:42.559Z' updated_by: elastic page: 1 per_page: 10 total: 1 schema: additionalProperties: false type: object properties: data: items: $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_response' type: array page: type: number per_page: type: number total: type: number required: - page - per_page - total - data description: Indicates a successful call. '400': description: Indicates an invalid schema or parameters. '403': description: Indicates that this call is forbidden. summary: Get information about rules tags: - alerting x-metaTags: - content: Kibana name: product_name description: '**Spaces method and path for this operation:**
get /s/{space_id}/api/alerting/rules/_find
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information.' /api/alerting/rules/backfill/_find: post: operationId: post-alerting-rules-backfill-find parameters: - description: A required header to protect against CSRF attacks in: header name: kbn-xsrf required: true schema: example: 'true' type: string - description: The end date for filtering backfills. in: query name: end required: false schema: type: string - description: The page number to return. in: query name: page required: false schema: default: 1 minimum: 1 type: number - description: The number of backfills to return per page. in: query name: per_page required: false schema: default: 10 minimum: 0 type: number - description: A comma-separated list of rule identifiers. in: query name: rule_ids required: false schema: type: string - description: The initiator of the backfill, either `user` for manual backfills or `system` for automatic gap fills. in: query name: initiator required: false schema: enum: - user - system type: string - description: The start date for filtering backfills. in: query name: start required: false schema: type: string - description: The field to sort backfills by. in: query name: sort_field required: false schema: enum: - createdAt - start type: string - description: The sort order. in: query name: sort_order required: false schema: enum: - asc - desc type: string responses: '200': content: application/json: examples: findBackfillResponse: summary: Find backfills response value: data: - created_at: '2024-01-30T00:00:00.000Z' duration: 12h enabled: true id: 85bdf571-f4fb-4666-a8d2-e05e1220ebc6 initiator: user rule: api_key_owner: elastic consumer: alerts created_at: '2022-12-05T23:40:33.132Z' created_by: elastic enabled: true id: 3583a470-74f6-11ed-9801-35303b735aef name: my alert params: aggField: sheet.version aggType: avg groupBy: top index: - test-index termField: name.keyword termSize: 6 threshold: - 1000 thresholdComparator: '>' timeField: '@timestamp' timeWindowSize: 5 timeWindowUnit: m revision: 0 rule_type_id: .index-threshold schedule: interval: 1m tags: - cpu updated_at: '2022-12-05T23:40:33.132Z' updated_by: elastic schedule: - interval: 12h run_at: '2024-01-01T12:00:00.000Z' status: pending - interval: 12h run_at: '2024-01-02T00:00:00.000Z' status: pending space_id: default start: '2024-01-01T00:00:00.000Z' status: pending page: 1 per_page: 10 total: 1 schema: $ref: '#/components/schemas/Kibana_HTTP_APIs_find_backfill_response' description: Indicates a successful call. '400': description: Indicates an invalid schema or parameters. '403': description: Indicates that this call is forbidden. summary: Find backfills for rules tags: - alerting x-metaTags: - content: Kibana name: product_name description: '**Spaces method and path for this operation:**
post /s/{space_id}/api/alerting/rules/backfill/_find
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information.' /api/alerting/rules/backfill/_schedule: post: operationId: post-alerting-rules-backfill-schedule parameters: - description: A required header to protect against CSRF attacks in: header name: kbn-xsrf required: true schema: example: 'true' type: string requestBody: content: application/json: examples: scheduleBackfillRequest: summary: Schedule a backfill for an index threshold rule value: - ranges: - end: '2024-01-02T00:00:00.000Z' start: '2024-01-01T00:00:00.000Z' rule_id: 3583a470-74f6-11ed-9801-35303b735aef schema: items: additionalProperties: false type: object properties: ranges: items: additionalProperties: false type: object properties: end: type: string start: type: string required: - start - end type: array rule_id: type: string run_actions: type: boolean required: - rule_id - ranges maxItems: 100 minItems: 1 type: array responses: '200': content: application/json: examples: scheduleBackfillResponse: summary: Schedule backfill response value: - created_at: '2024-01-30T00:00:00.000Z' duration: 12h enabled: true id: 85bdf571-f4fb-4666-a8d2-e05e1220ebc6 initiator: user rule: api_key_owner: elastic consumer: alerts created_at: '2022-12-05T23:40:33.132Z' created_by: elastic enabled: true id: 3583a470-74f6-11ed-9801-35303b735aef name: my alert params: aggField: sheet.version aggType: avg groupBy: top index: - test-index termField: name.keyword termSize: 6 threshold: - 1000 thresholdComparator: '>' timeField: '@timestamp' timeWindowSize: 5 timeWindowUnit: m revision: 0 rule_type_id: .index-threshold schedule: interval: 1m tags: - cpu updated_at: '2022-12-05T23:40:33.132Z' updated_by: elastic schedule: - interval: 12h run_at: '2024-01-01T12:00:00.000Z' status: pending - interval: 12h run_at: '2024-01-02T00:00:00.000Z' status: pending space_id: default start: '2024-01-01T00:00:00.000Z' status: pending schema: items: anyOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_backfill_response' - $ref: '#/components/schemas/Kibana_HTTP_APIs_backfill_error_response' type: array description: Indicates a successful call. '400': description: Indicates an invalid schema or parameters. '403': description: Indicates that this call is forbidden. '404': description: Indicates a rule with the given ID does not exist. summary: Schedule a backfill for rules tags: - alerting x-metaTags: - content: Kibana name: product_name description: '**Spaces method and path for this operation:**
post /s/{space_id}/api/alerting/rules/backfill/_schedule
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information.' /api/alerting/rules/backfill/{id}: delete: operationId: delete-alerting-rules-backfill-id parameters: - description: A required header to protect against CSRF attacks in: header name: kbn-xsrf required: true schema: example: 'true' type: string - description: The identifier for the backfill. in: path name: id required: true schema: type: string responses: '204': description: Indicates a successful call. '400': description: Indicates an invalid schema or parameters. '403': description: Indicates that this call is forbidden. '404': description: Indicates a backfill with the given ID does not exist. summary: Delete a backfill by ID tags: - alerting x-metaTags: - content: Kibana name: product_name description: '**Spaces method and path for this operation:**
delete /s/{space_id}/api/alerting/rules/backfill/{id}
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information.' get: operationId: get-alerting-rules-backfill-id parameters: - description: The identifier for the backfill. in: path name: id required: true schema: type: string responses: '200': content: application/json: examples: getBackfillResponse: summary: Get a backfill for an index threshold rule value: created_at: '2024-01-30T00:00:00.000Z' duration: 12h enabled: true id: 85bdf571-f4fb-4666-a8d2-e05e1220ebc6 initiator: user rule: api_key_owner: elastic consumer: alerts created_at: '2022-12-05T23:40:33.132Z' created_by: elastic enabled: true id: 3583a470-74f6-11ed-9801-35303b735aef name: my alert params: aggField: sheet.version aggType: avg groupBy: top index: - test-index termField: name.keyword termSize: 6 threshold: - 1000 thresholdComparator: '>' timeField: '@timestamp' timeWindowSize: 5 timeWindowUnit: m revision: 0 rule_type_id: .index-threshold schedule: interval: 1m tags: - cpu updated_at: '2022-12-05T23:40:33.132Z' updated_by: elastic schedule: - interval: 12h run_at: '2024-01-01T12:00:00.000Z' status: pending - interval: 12h run_at: '2024-01-02T00:00:00.000Z' status: pending space_id: default start: '2024-01-01T00:00:00.000Z' status: pending schema: $ref: '#/components/schemas/Kibana_HTTP_APIs_backfill_response' description: Indicates a successful call. '400': description: Indicates an invalid schema or parameters. '403': description: Indicates that this call is forbidden. '404': description: Indicates a backfill with the given ID does not exist. summary: Get a backfill by ID tags: - alerting x-metaTags: - content: Kibana name: product_name description: '**Spaces method and path for this operation:**
get /s/{space_id}/api/alerting/rules/backfill/{id}
Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information.' components: schemas: Kibana_HTTP_APIs_xpack-uptime-alerts-tlscertificate-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: false description: The parameters for the uptime tls rule. These parameters are appropriate when `rule_type_id` is `xpack.uptime.alerts.tlsCertificate`. properties: certAgeThreshold: type: number certExpirationThreshold: type: number search: type: string stackVersion: type: string title: Uptime TLS Rule Params type: object rule_type_id: enum: - xpack.uptime.alerts.tlsCertificate type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: Uptime TLS certificate type: object Kibana_HTTP_APIs_monitoring-alert-license-expiration-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: true description: The parameters for the license expiration rule. These parameters are appropriate when `rule_type_id` is `monitoring_alert_license_expiration`. properties: duration: type: string filterQuery: type: string filterQueryText: type: string limit: type: string threshold: type: number required: - duration title: License Expiration Rule Params type: object rule_type_id: enum: - monitoring_alert_license_expiration type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: License expiration type: object Kibana_HTTP_APIs_monitoring-alert-elasticsearch-version-mismatch-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: true description: The parameters for the ES version mismatch rule. These parameters are appropriate when `rule_type_id` is `monitoring_alert_elasticsearch_version_mismatch`. properties: duration: type: string filterQuery: type: string filterQueryText: type: string limit: type: string threshold: type: number required: - duration title: ES Version Mismatch Rule Params type: object rule_type_id: enum: - monitoring_alert_elasticsearch_version_mismatch type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: Elasticsearch version mismatch type: object Kibana_HTTP_APIs_new_rule: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: {} default: {} description: The parameters for the rule. type: object rule_type_id: description: The rule type identifier. type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id title: new_rule type: object Kibana_HTTP_APIs_find_backfill_response: additionalProperties: false properties: data: items: $ref: '#/components/schemas/Kibana_HTTP_APIs_backfill_response' type: array page: type: number per_page: type: number total: type: number required: - page - per_page - total - data title: find_backfill_response type: object Kibana_HTTP_APIs_xpack-ml-anomaly-detection-jobs-health-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: false description: The parameters for the anomaly detection jobs health rule. These parameters are appropriate when `rule_type_id` is `xpack.ml.anomaly_detection_jobs_health"`. properties: excludeJobs: additionalProperties: false default: null type: - object - 'null' properties: groupIds: default: [] items: type: string type: array jobIds: default: [] items: type: string type: array includeJobs: additionalProperties: false type: object properties: groupIds: default: [] items: type: string type: array jobIds: default: [] items: type: string type: array testsConfig: additionalProperties: false default: null type: - object - 'null' properties: behindRealtime: additionalProperties: false default: null type: - object - 'null' properties: enabled: default: true type: boolean timeInterval: default: null type: - string - 'null' datafeed: additionalProperties: false default: null type: - object - 'null' properties: enabled: default: true type: boolean delayedData: additionalProperties: false default: null type: - object - 'null' properties: docsCount: default: null minimum: 1 type: - number - 'null' docsCountPercentage: default: null maximum: 100 minimum: 0 type: - number - 'null' enabled: default: true type: boolean thresholdType: enum: - count - percentage type: string timeInterval: default: null type: - string - 'null' errorMessages: additionalProperties: false default: null type: - object - 'null' properties: enabled: default: true type: boolean mml: additionalProperties: false default: null type: - object - 'null' properties: enabled: default: true type: boolean required: - includeJobs title: Anomaly Detection Jobs Health Rule Params type: object rule_type_id: enum: - xpack.ml.anomaly_detection_jobs_health type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: Anomaly detection jobs health type: object Kibana_HTTP_APIs_update_rule: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_update_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: {} default: {} description: The parameters for the rule. type: object schedule: additionalProperties: false type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] items: description: The tags for the rule. type: string type: array throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - schedule title: update_rule type: object Kibana_HTTP_APIs_apm-transaction-duration-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: false description: The parameters for the transaction duration rule. These parameters are appropriate when `rule_type_id` is `apm.transaction_duration`. properties: aggregationType: description: The type of aggregation to perform. enum: - avg - 95th - 99th type: string environment: description: Filter the rule to apply to a specific environment. type: string groupBy: items: description: Perform a composite aggregation against the selected fields. When any of these groups match the selected rule conditions, an alert is triggered per group. type: string type: array searchConfiguration: additionalProperties: false type: object properties: query: additionalProperties: false type: object properties: language: type: string query: anyOf: - type: string - additionalProperties: {} type: object required: - query - language required: - query serviceName: description: Filter the rule to apply to a specific service. type: string threshold: description: The latency threshold value. type: number transactionName: description: Filter the rule to apply to a specific transaction name. type: string transactionType: description: Filter the rule to apply to a specific transaction type. type: string useKqlFilter: description: A Kibana Query Language (KQL) expression thats limits the scope of alerts. type: boolean windowSize: description: The size of the time window (in `windowUnit` units), which determines how far back to search for documents. Generally it should be a value higher than the rule check interval to avoid gaps in detection. type: number windowUnit: description: 'The type of units for the time window. For example: minutes, hours, or days.' type: string required: - windowSize - windowUnit - threshold - aggregationType - environment title: Transaction Duration Rule Params type: object rule_type_id: enum: - apm.transaction_duration type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: Transaction duration type: object Kibana_HTTP_APIs_monitoring-alert-jvm-memory-usage-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: true description: The parameters for the memory usage rule. These parameters are appropriate when `rule_type_id` is `monitoring_alert_jvm_memory_usage`. properties: duration: type: string filterQuery: type: string filterQueryText: type: string limit: type: string threshold: type: number required: - duration title: Memory Usage Rule Params type: object rule_type_id: enum: - monitoring_alert_jvm_memory_usage type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: JVM memory usage type: object Kibana_HTTP_APIs_logs-alert-document-count-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: anyOf: - additionalProperties: false type: object properties: count: additionalProperties: false type: object properties: comparator: enum: - more than - more than or equals - less than - less than or equals - equals - does not equal - matches - does not match - matches phrase - does not match phrase type: string value: type: number required: - comparator - value criteria: items: additionalProperties: false type: object properties: comparator: enum: - more than - more than or equals - less than - less than or equals - equals - does not equal - matches - does not match - matches phrase - does not match phrase type: string field: type: string value: anyOf: - type: string - type: number required: - field - comparator - value type: array groupBy: items: type: string type: array logView: additionalProperties: false type: object properties: logViewId: type: string type: enum: - log-view-reference type: string required: - logViewId - type timeSize: type: number timeUnit: enum: - s - m - h - d type: string required: - criteria - count - timeUnit - timeSize - logView - additionalProperties: false type: object properties: count: additionalProperties: false type: object properties: comparator: enum: - more than - more than or equals - less than - less than or equals - equals - does not equal - matches - does not match - matches phrase - does not match phrase type: string value: type: number required: - comparator - value criteria: items: items: additionalProperties: false type: object properties: comparator: enum: - more than - more than or equals - less than - less than or equals - equals - does not equal - matches - does not match - matches phrase - does not match phrase type: string field: type: string value: anyOf: - type: string - type: number required: - field - comparator - value type: array maxItems: 2 minItems: 2 type: array groupBy: items: type: string type: array logView: additionalProperties: false type: object properties: logViewId: type: string type: enum: - log-view-reference type: string required: - logViewId - type timeSize: type: number timeUnit: enum: - s - m - h - d type: string required: - criteria - count - timeUnit - timeSize - logView description: The parameters for the log threshold rule. These parameters are appropriate when `rule_type_id` is `logs.alert.document.count`. title: Log Threshold Rule Params rule_type_id: enum: - logs.alert.document.count type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: Log threshold type: object Kibana_HTTP_APIs_rule_response: additionalProperties: false properties: actions: items: additionalProperties: false type: object properties: alerts_filter: additionalProperties: false description: Defines a period that limits whether the action runs. type: object properties: query: $ref: '#/components/schemas/Kibana_HTTP_APIs_alerts_filter_query' timeframe: additionalProperties: false type: object properties: days: description: Defines the days of the week that the action can run, represented as an array of numbers. For example, `1` represents Monday. An empty array is equivalent to specifying all the days of the week. items: enum: - 1 - 2 - 3 - 4 - 5 - 6 - 7 type: integer type: array hours: additionalProperties: false type: object properties: end: description: The end of the time frame, in 24-hour notation (`hh:mm`). type: string start: description: The start of the time frame, in 24-hour notation (`hh:mm`). type: string required: - start - end timezone: description: The ISO time zone for the `hours` values. Values such as `UTC` and `UTC+1` also work but lack built-in support for daylight savings time and are not recommended. type: string required: - days - hours - timezone connector_type_id: description: The type of connector. This property appears in responses but cannot be set in requests. type: string frequency: additionalProperties: false type: object properties: notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval type: string summary: description: Indicates whether the action is a summary. type: boolean throttle: default: null description: The throttle interval defines how frequently rule actions are triggered. It is specified in seconds, minutes, hours, or days and only applies when 'notify_when' is set to 'onThrottleInterval'. You cannot set the throttle interval at both the rule and action level. The recommended approach is to set it for each action individually. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - summary - notify_when group: description: The group name, which affects when the action runs (for example, when the threshold is met or when the alert is recovered). Each rule type has a list of valid action group names. If you don't need to group actions, set to `default`. type: string id: description: The identifier for the connector saved object. type: string params: additionalProperties: {} description: The parameters for the action, which are sent to the connector. The `params` are handled as Mustache templates and passed a default set of context. type: object use_alert_data_for_template: description: Indicates whether to use alert data as a template. type: boolean uuid: description: A universally unique identifier (UUID) for the action. type: string required: - id - connector_type_id - params type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active api_key_created_by_user: description: Indicates whether the API key that is associated with the rule was created by the user. type: - boolean - 'null' api_key_owner: default: null description: The owner of the API key that is associated with the rule and used to run background tasks. type: - string - 'null' artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id type: array investigation_guide: additionalProperties: false type: object properties: blob: description: User-created content that describes alert causes and remediation. type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string created_at: description: The date and time that the rule was created. type: string created_by: default: null description: The identifier for the user that created the rule. type: - string - 'null' enabled: description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean execution_status: additionalProperties: false type: object properties: error: additionalProperties: false type: object properties: message: description: Error message. type: string reason: description: Reason for error. enum: - read - decrypt - execute - unknown - license - timeout - disabled - validate type: string required: - reason - message last_duration: description: Duration of last rule execution. type: number last_execution_date: description: The date and time of the last rule execution. type: string status: description: Status of rule execution. enum: - ok - active - error - warning - pending - unknown type: string warning: additionalProperties: false type: object properties: message: description: Warning message. type: string reason: description: Reason for warning. enum: - maxExecutableActions - maxAlerts - maxQueuedActions - ruleExecution type: string required: - reason - message required: - status - last_execution_date flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' id: description: The identifier for the rule. type: string last_run: additionalProperties: false type: - object - 'null' properties: alerts_count: additionalProperties: false type: object properties: active: description: Number of active alerts during last run. type: - number - 'null' ignored: description: Number of ignored alerts during last run. type: - number - 'null' new: description: Number of new alerts during last run. type: - number - 'null' recovered: description: Number of recovered alerts during last run. type: - number - 'null' outcome: description: Outcome of the last rule run. Value can be succeeded, warning, or failed. enum: - succeeded - warning - failed type: string outcome_msg: items: description: Outcome message generated during last rule run. type: string type: - array - 'null' outcome_order: description: Order of the outcome. type: number warning: description: Warning of last rule execution. enum: - read - decrypt - execute - unknown - license - timeout - disabled - validate - maxExecutableActions - maxAlerts - maxQueuedActions - ruleExecution - null type: - string - 'null' required: - outcome - alerts_count mapped_params: additionalProperties: {} type: object mute_all: description: Indicates whether all alerts are muted. type: boolean muted_alert_ids: items: description: 'List of identifiers of muted alerts. ' type: string type: array name: description: ' The name of the rule.' type: string next_run: description: Date and time of the next rule run. type: - string - 'null' notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: {} description: The parameters for the rule. type: object revision: description: The rule revision number. type: number rule_type_id: description: The rule type identifier. type: string running: description: Indicates whether the rule is running. type: - boolean - 'null' schedule: additionalProperties: false type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval scheduled_task_id: description: Identifier of the scheduled task. type: string tags: items: description: The tags for the rule. type: string type: array throttle: deprecated: true description: Deprecated in 8.13.0. Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' updated_at: description: The date and time of the latest updates to the rule. type: string updated_by: default: null description: The identifier for the user who was the last to update the rule. type: - string - 'null' required: - id - enabled - name - tags - rule_type_id - consumer - schedule - actions - params - created_at - updated_at - mute_all - muted_alert_ids - execution_status - revision title: rule_response type: object Kibana_HTTP_APIs_xpack-ml-anomaly-detection-alert-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: false description: The parameters for the anomaly detection rule. These parameters are appropriate when `rule_type_id` is `xpack.ml.anomaly_detection_alert"`. properties: includeInterim: default: true type: boolean jobSelection: additionalProperties: false type: object properties: groupIds: default: [] items: type: string type: array jobIds: default: [] items: type: string type: array kqlQueryString: default: null type: - string - 'null' lookbackInterval: default: null type: - string - 'null' resultType: enum: - record - bucket - influencer type: string severity: maximum: 100 minimum: 0 type: number topNBuckets: default: null minimum: 1 type: - number - 'null' required: - jobSelection - severity - resultType title: Anomaly Detection Rule Params type: object rule_type_id: enum: - xpack.ml.anomaly_detection_alert type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: Anomaly detection type: object Alerting_fieldmap_properties: title: Field map objects in the get rule types response type: object properties: array: description: Indicates whether the field is an array. type: boolean dynamic: description: Indicates whether it is a dynamic field mapping. type: boolean format: description: 'Indicates the format of the field. For example, if the `type` is `date_range`, the `format` can be `epoch_millis||strict_date_optional_time`. ' type: string ignore_above: description: Specifies the maximum length of a string field. Longer strings are not indexed or stored. type: integer index: description: Indicates whether field values are indexed. type: boolean path: description: TBD type: string properties: additionalProperties: type: object properties: type: description: The data type for each object property. type: string description: 'Details about the object properties. This property is applicable when `type` is `object`. ' type: object required: description: Indicates whether the field is required. type: boolean scaling_factor: description: "The scaling factor to use when encoding values. This property is applicable when `type` is `scaled_float`. Values will be multiplied by this factor at index time and rounded to the closest long value. \n" type: integer type: description: Specifies the data type for the field. example: scaled_float type: string Kibana_HTTP_APIs_backfill_error_response: additionalProperties: false properties: error: additionalProperties: false type: object properties: message: type: string rule: additionalProperties: false type: object properties: id: type: string name: type: string required: - id status: type: number required: - message - rule required: - error title: backfill_error_response type: object Kibana_HTTP_APIs_schedule_request: additionalProperties: false properties: duration: description: 'The duration of the schedule. It allows values in `` format. `` is one of `d`, `h`, `m`, or `s` for hours, minutes, seconds. For example: `1d`, `5h`, `30m`, `5000s`.' maxLength: 100 type: string recurring: additionalProperties: false type: object properties: end: description: 'The end date of a recurring schedule, provided in ISO 8601 format and set to the UTC timezone. For example: `2025-04-01T00:00:00.000Z`.' maxLength: 100 type: string every: description: 'The interval and frequency of a recurring schedule. It allows values in `` format. `` is one of `d`, `w`, `M`, or `y` for days, weeks, months, years. For example: `15d`, `2w`, `3m`, `1y`.' maxLength: 100 type: string occurrences: description: The total number of recurrences of the schedule. minimum: 1 type: number onMonth: description: The specific months for a recurring schedule. Valid values are 1-12. items: maximum: 12 minimum: 1 type: number maxItems: 12 minItems: 1 type: array onMonthDay: description: The specific days of the month for a recurring schedule. Valid values are 1-31. items: maximum: 31 minimum: 1 type: number maxItems: 31 minItems: 1 type: array onWeekDay: description: The specific days of the week (`[MO,TU,WE,TH,FR,SA,SU]`) or nth day of month (`[+1MO, -3FR, +2WE, -4SA, -5SU]`) for a recurring schedule. items: maxLength: 10 type: string maxItems: 77 minItems: 1 type: array start: description: 'The start date and time of the schedule, provided in ISO 8601 format and set to the UTC timezone. For example: `2025-03-12T12:00:00.000Z`.' maxLength: 100 type: string timezone: description: The timezone of the schedule. The default timezone is UTC. maxLength: 64 type: string required: - start - duration title: schedule_request type: object Kibana_HTTP_APIs_datasetquality-degradeddocs-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: false description: The parameters for the degraded docs rule. These parameters are appropriate when `rule_type_id` is `datasetQuality.degradedDocs`. properties: comparator: type: string groupBy: items: type: string type: array searchConfiguration: additionalProperties: false type: object properties: index: type: string required: - index threshold: items: type: number type: array timeSize: type: number timeUnit: type: string required: - timeUnit - timeSize - threshold - comparator - searchConfiguration title: Degraded Docs Rule Params type: object rule_type_id: enum: - datasetQuality.degradedDocs type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: Degraded docs type: object Kibana_HTTP_APIs_new_rule_action: additionalProperties: false description: An action that runs under defined conditions. properties: alerts_filter: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action_alerts_filter' frequency: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action_frequency' group: description: The group name, which affects when the action runs (for example, when the threshold is met or when the alert is recovered). Each rule type has a list of valid action group names. If you don't need to group actions, set to `default`. type: string id: description: The identifier for the connector saved object. type: string params: additionalProperties: {} default: {} description: The parameters for the action, which are sent to the connector. The `params` are handled as Mustache templates and passed a default set of context. type: object use_alert_data_for_template: description: Indicates whether to use alert data as a template. type: boolean uuid: description: A universally unique identifier (UUID) for the action. type: string required: - id title: new_rule_action type: object Kibana_HTTP_APIs_index-threshold-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: false description: The parameters for the index threshold rule. These parameters are appropriate when `rule_type_id` is `.index-threshold`. properties: aggField: description: The name of the numeric field that is used in the aggregation. This property is required when `aggType` is `avg`, `max`, `min` or `sum`. minLength: 1 type: string aggType: default: count description: The type of aggregation to perform. type: string filterKuery: description: A Kibana Query Language (KQL) expression thats limits the scope of alerts. type: string groupBy: default: all description: Indicates whether the aggregation is applied over all documents (`all`) or split into groups (`top`) using a grouping field (`termField`). If grouping is used, an alert will be created for each group when it exceeds the threshold; only the top groups (up to `termSize` number of groups) are checked. type: string index: anyOf: - minLength: 1 type: string - items: minLength: 1 type: string minItems: 1 type: array description: The indices to query. termField: description: The names of up to four fields that are used for grouping the aggregation. This property is required when `groupBy` is `top`. minLength: 1 type: string termSize: description: This property is required when `groupBy` is `top`. It specifies the number of groups to check against the threshold and therefore limits the number of alerts on high cardinality fields. minimum: 1 type: number threshold: items: type: number maxItems: 2 minItems: 1 type: array thresholdComparator: description: 'The comparison function for the threshold. For example: greater than, less than, greater than or equal to, between, or not between.' enum: - '>' - < - '>=' - <= - between - notBetween type: string timeField: description: The field that is used to calculate the time window. minLength: 1 type: string timeWindowSize: description: The size of the time window (in `timeWindowUnit` units), which determines how far back to search for documents. Generally it should be a value higher than the rule check interval to avoid gaps in detection. minimum: 1 type: number timeWindowUnit: description: 'The type of units for the time window. For example: seconds, minutes, hours, or days.' type: string required: - index - timeField - timeWindowSize - timeWindowUnit - thresholdComparator - threshold title: Index Threshold Rule Params type: object rule_type_id: enum: - .index-threshold type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: Index threshold type: object Kibana_HTTP_APIs_monitoring-ccr-read-exceptions-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: true description: The parameters for the CCR read exceptions rule. These parameters are appropriate when `rule_type_id` is `monitoring_ccr_read_exceptions`. properties: duration: type: string filterQuery: type: string filterQueryText: type: string limit: type: string threshold: type: number required: - duration title: CCR Read Exceptions Rule Params type: object rule_type_id: enum: - monitoring_ccr_read_exceptions type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: CCR read exceptions type: object Kibana_HTTP_APIs_slo-rules-burnrate-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: false description: The parameters for the slo burn rate rule. These parameters are appropriate when `rule_type_id` is `slo.rules.burnRate`. properties: dependencies: items: additionalProperties: false type: object properties: actionGroupsToSuppressOn: items: type: string type: array ruleId: type: string required: - ruleId - actionGroupsToSuppressOn type: array sloId: type: string windows: items: additionalProperties: false type: object properties: actionGroup: type: string burnRateThreshold: type: number id: type: string longWindow: additionalProperties: false type: object properties: unit: type: string value: type: number required: - value - unit maxBurnRateThreshold: default: null type: - number - 'null' shortWindow: additionalProperties: false type: object properties: unit: type: string value: type: number required: - value - unit required: - id - burnRateThreshold - longWindow - shortWindow - actionGroup type: array required: - sloId - windows title: SLO Burn Rate Rule Params type: object rule_type_id: enum: - slo.rules.burnRate type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: SLO burn rate type: object Kibana_HTTP_APIs_new_rule_action_frequency: additionalProperties: false properties: notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval type: string summary: description: Indicates whether the action is a summary. type: boolean throttle: default: null description: The throttle interval defines how frequently rule actions are triggered. It is specified in seconds, minutes, hours, or days and only applies when `notify_when` is set to `onThrottleInterval`. You cannot set the throttle interval at both the rule and action level. The recommended approach is to set it for each action individually. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - summary - notify_when title: new_rule_action_frequency type: object Kibana_HTTP_APIs_observability-rules-custom-threshold-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: true description: The parameters for the custom threshold rule. These parameters are appropriate when `rule_type_id` is `observability.rules.custom_threshold`. properties: alertOnGroupDisappear: type: boolean alertOnNoData: type: boolean criteria: items: additionalProperties: false type: object properties: aggType: enum: - custom type: string comparator: type: string equation: type: string label: type: string metrics: items: anyOf: - additionalProperties: false type: object properties: aggType: type: string field: type: string filter: type: string name: type: string required: - name - aggType - field - additionalProperties: false type: object properties: aggType: enum: - count type: string filter: type: string name: type: string required: - name - aggType type: array threshold: items: type: number type: array timeSize: type: number timeUnit: type: string warningComparator: type: string warningThreshold: items: description: The threshold value that is used with the `warningComparator`. If the `warningComparator` is `between`, you must specify the boundary values. type: number maxItems: 2 type: array required: - threshold - comparator - timeUnit - timeSize - metrics type: array groupBy: anyOf: - type: string - items: type: string type: array noDataBehavior: enum: - recover - remainActive - alertOnNoData type: string searchConfiguration: additionalProperties: false type: object properties: filter: items: additionalProperties: false type: object properties: meta: additionalProperties: {} type: object query: additionalProperties: {} type: object required: - meta type: array index: anyOf: - type: string - additionalProperties: false type: object properties: allowHidden: type: boolean allowNoIndex: type: boolean fieldAttrs: additionalProperties: additionalProperties: false type: object properties: count: type: number customDescription: maxLength: 300 type: string customLabel: type: string type: object fieldFormats: additionalProperties: additionalProperties: false type: object properties: id: type: string params: {} required: - params type: object fields: additionalProperties: additionalProperties: false type: object properties: aggregatable: type: boolean count: minimum: 0 type: number customDescription: maxLength: 300 type: string customLabel: type: string esTypes: items: type: string type: array format: additionalProperties: false type: object properties: id: type: string params: {} required: - params name: maxLength: 1000 type: string readFromDocValues: type: boolean runtimeField: anyOf: - additionalProperties: false type: object properties: customDescription: maxLength: 300 type: string customLabel: type: string format: additionalProperties: false type: object properties: id: type: string params: {} required: - params popularity: minimum: 0 type: number script: additionalProperties: false type: object properties: source: type: string required: - source type: enum: - keyword - long - double - date - ip - boolean - geo_point type: string required: - type - additionalProperties: false type: object properties: fields: additionalProperties: additionalProperties: false type: object properties: customDescription: maxLength: 300 type: string customLabel: type: string format: additionalProperties: false type: object properties: id: type: string params: {} required: - params popularity: minimum: 0 type: number type: enum: - keyword - long - double - date - ip - boolean - geo_point type: string required: - type type: object script: additionalProperties: false type: object properties: source: type: string required: - source type: enum: - composite type: string required: - type script: maxLength: 1000000 type: string scripted: type: boolean searchable: type: boolean shortDotsEnable: type: boolean subType: additionalProperties: false type: object properties: multi: additionalProperties: false type: object properties: parent: type: string required: - parent nested: additionalProperties: false type: object properties: path: type: string required: - path type: default: string maxLength: 1000 type: string required: - name type: object id: type: string managed: type: boolean name: type: string namespaces: items: type: string type: array runtimeFieldMap: additionalProperties: anyOf: - additionalProperties: false type: object properties: customDescription: maxLength: 300 type: string customLabel: type: string format: additionalProperties: false type: object properties: id: type: string params: {} required: - params popularity: minimum: 0 type: number script: additionalProperties: false type: object properties: source: type: string required: - source type: enum: - keyword - long - double - date - ip - boolean - geo_point type: string required: - type - additionalProperties: false type: object properties: fields: additionalProperties: additionalProperties: false type: object properties: customDescription: maxLength: 300 type: string customLabel: type: string format: additionalProperties: false type: object properties: id: type: string params: {} required: - params popularity: minimum: 0 type: number type: enum: - keyword - long - double - date - ip - boolean - geo_point type: string required: - type type: object script: additionalProperties: false type: object properties: source: type: string required: - source type: enum: - composite type: string required: - type type: object sourceFilters: items: additionalProperties: false type: object properties: clientId: anyOf: - type: string - type: number value: type: string required: - value type: array timeFieldName: type: string title: type: string type: type: string typeMeta: additionalProperties: true type: object properties: {} version: type: string required: - title query: additionalProperties: false type: object properties: language: type: string query: type: string required: - language - query required: - index - query required: - criteria - searchConfiguration title: Custom Threshold Rule Params type: object rule_type_id: enum: - observability.rules.custom_threshold type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: Custom threshold type: object Kibana_HTTP_APIs_monitoring-alert-missing-monitoring-data-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: true description: The parameters for the missing monitoring data rule. These parameters are appropriate when `rule_type_id` is `monitoring_alert_missing_monitoring_data`. properties: duration: type: string filterQuery: type: string filterQueryText: type: string limit: type: string threshold: type: number required: - duration title: Missing Monitoring Data Rule Params type: object rule_type_id: enum: - monitoring_alert_missing_monitoring_data type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: Missing monitoring data type: object Kibana_HTTP_APIs_backfill_response: additionalProperties: false properties: created_at: type: string duration: type: string enabled: type: boolean end: type: string id: type: string initiator: enum: - user - system type: string initiator_id: type: string rule: additionalProperties: false type: object properties: api_key_created_by_user: type: - boolean - 'null' api_key_owner: default: null type: - string - 'null' consumer: type: string created_at: type: string created_by: default: null type: - string - 'null' enabled: type: boolean id: type: string name: type: string params: additionalProperties: {} description: The parameters for the rule. type: object revision: type: number rule_type_id: type: string schedule: additionalProperties: false type: object properties: interval: type: string required: - interval tags: items: type: string type: array updated_at: type: string updated_by: default: null type: - string - 'null' required: - id - name - tags - rule_type_id - params - consumer - enabled - schedule - created_at - updated_at - revision schedule: items: additionalProperties: false type: object properties: interval: type: string run_at: type: string status: enum: - complete - pending - running - error - timeout type: string required: - run_at - status - interval type: array space_id: type: string start: type: string status: enum: - complete - pending - running - error - timeout type: string required: - id - created_at - duration - enabled - rule - space_id - initiator - start - status - schedule title: backfill_response type: object Kibana_HTTP_APIs_xpack-synthetics-alerts-monitorstatus-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: false description: The parameters for the synthetics monitor status rule. These parameters are appropriate when `rule_type_id` is `xpack.synthetics.alerts.monitorStatus`. properties: condition: additionalProperties: false type: object properties: alertOnNoData: type: boolean downThreshold: type: number groupBy: type: string includeRetests: type: boolean locationsThreshold: type: number recoveryStrategy: enum: - firstUp - conditionNotMet type: string window: anyOf: - additionalProperties: false type: object properties: time: additionalProperties: false type: object properties: size: default: 5 type: number unit: default: m enum: - s - m - h - d type: string required: - time - additionalProperties: false type: object properties: numberOfChecks: default: 5 maximum: 100 minimum: 1 type: number required: - window kqlQuery: type: string locations: items: type: string type: array monitorIds: items: type: string type: array monitorTypes: items: type: string type: array projects: items: type: string type: array tags: items: type: string type: array title: Synthetics Monitor Status Rule Params type: object rule_type_id: enum: - xpack.synthetics.alerts.monitorStatus type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: Synthetics monitor status type: object Kibana_HTTP_APIs_metrics-alert-threshold-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: true description: The parameters for the metric threshold rule. These parameters are appropriate when `rule_type_id` is `metrics.alert.threshold`. properties: alertOnGroupDisappear: description: If true, an alert occurs if a group that previously reported metrics does not report them again over the expected time period. This check is not recommended for dynamically scaling infrastructures that might rapidly start and stop nodes automatically. type: boolean alertOnNoData: description: If true, an alert occurs if the metrics do not report any data over the expected period or if the query fails. type: boolean criteria: items: anyOf: - additionalProperties: false type: object properties: aggType: enum: - count type: string comparator: type: string threshold: description: The threshold value that is used with the `comparator`. If the `comparator` is `between`, you must specify the boundary values. items: type: number type: array timeSize: description: The size of the time window (in `timeUnit` units), which determines how far back to search for documents. Generally it should be a value higher than the rule check interval to avoid gaps in detection. type: number timeUnit: description: 'The type of units for the time window: seconds, minutes, hours, or days.' type: string warningComparator: type: string warningThreshold: items: description: The threshold value that is used with the `warningComparator`. If the `warningComparator` is `between`, you must specify the boundary values. type: number type: array required: - threshold - comparator - timeUnit - timeSize - aggType - additionalProperties: false type: object properties: aggType: type: string comparator: type: string metric: type: string threshold: description: The threshold value that is used with the `comparator`. If the `comparator` is `between`, you must specify the boundary values. items: type: number type: array timeSize: description: The size of the time window (in `timeUnit` units), which determines how far back to search for documents. Generally it should be a value higher than the rule check interval to avoid gaps in detection. type: number timeUnit: description: 'The type of units for the time window: seconds, minutes, hours, or days.' type: string warningComparator: type: string warningThreshold: items: description: The threshold value that is used with the `warningComparator`. If the `warningComparator` is `between`, you must specify the boundary values. type: number type: array required: - threshold - comparator - timeUnit - timeSize - metric - aggType - additionalProperties: false type: object properties: aggType: enum: - custom type: string comparator: type: string customMetrics: items: anyOf: - additionalProperties: false type: object properties: aggType: type: string field: type: string name: type: string required: - name - aggType - field - additionalProperties: false type: object properties: aggType: enum: - count type: string filter: type: string name: type: string required: - name - aggType type: array equation: type: string label: type: string threshold: description: The threshold value that is used with the `comparator`. If the `comparator` is `between`, you must specify the boundary values. items: type: number type: array timeSize: description: The size of the time window (in `timeUnit` units), which determines how far back to search for documents. Generally it should be a value higher than the rule check interval to avoid gaps in detection. type: number timeUnit: description: 'The type of units for the time window: seconds, minutes, hours, or days.' type: string warningComparator: type: string warningThreshold: items: description: The threshold value that is used with the `warningComparator`. If the `warningComparator` is `between`, you must specify the boundary values. type: number type: array required: - threshold - comparator - timeUnit - timeSize - aggType - customMetrics type: array filterQuery: description: A query that limits the scope of the rule. The rule evaluates only metric data that matches the query. type: string groupBy: anyOf: - type: string - items: type: string type: array description: 'Create an alert for every unique value of the specified fields. For example, you can create a rule per host or every mount point of each host. IMPORTANT: If you include the same field in both the `filterQuery` and `groupBy`, you might receive fewer results than you expect. For example, if you filter by `cloud.region: us-east`, grouping by `cloud.region` will have no effect because the filter query can match only one region.' sourceId: type: string required: - criteria - sourceId title: Metric Threshold Rule Params type: object rule_type_id: enum: - metrics.alert.threshold type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: Metric threshold type: object Kibana_HTTP_APIs_update_rule_action_frequency: additionalProperties: false properties: notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval type: string summary: description: Indicates whether the action is a summary. type: boolean throttle: default: null description: The throttle interval defines how frequently rule actions are triggered. It is specified in seconds, minutes, hours, or days and only applies when `notify_when` is set to `onThrottleInterval`. You cannot set the throttle interval at both the rule and action level. The recommended approach is to set it for each action individually. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - summary - notify_when title: update_rule_action_frequency type: object Kibana_HTTP_APIs_rule_flapping: additionalProperties: false description: When flapping detection is turned on, alerts that switch quickly between active and recovered states are identified as “flapping” and notifications are reduced. properties: enabled: description: Determines whether the rule can enter the flapping state. By default, rules can enter the flapping state. type: boolean look_back_window: description: The minimum number of runs in which the threshold must be met. maximum: 20 minimum: 2 type: number status_change_threshold: description: The minimum number of times an alert must switch states within the defined look back window time. maximum: 20 minimum: 2 type: number required: - look_back_window - status_change_threshold title: rule_flapping type: object Kibana_HTTP_APIs_es-query-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: false description: The parameters for the ES query rule. These parameters are appropriate when `rule_type_id` is `.es-query`. properties: aggField: description: The name of the numeric field that is used in the aggregation. This property is required when `aggType` is `avg`, `max`, `min` or `sum`. minLength: 1 type: string aggType: default: count description: The type of aggregation to perform. type: string esqlQuery: anyOf: - items: {} type: array - type: boolean - type: number - type: object - type: string description: The query definition in Elasticsearch Query Language. oneOf: - additionalProperties: false type: object properties: esql: minLength: 1 type: string required: - esql - not: {} esQuery: anyOf: - items: {} type: array - type: boolean - type: number - type: object - type: string oneOf: - minLength: 1 type: string - not: {} excludeHitsFromPreviousRun: default: true description: Indicates whether to exclude matches from previous runs. If `true`, you can avoid alert duplication by excluding documents that have already been detected by the previous rule run. This option is not available when a grouping field is specified. type: boolean groupBy: default: all description: Indicates whether the aggregation is applied over all documents (`all`), grouped by row (`row`), or split into groups (`top`) using a grouping field (`termField`) where only the top groups (up to `termSize` number of groups) are checked. If grouping is used, an alert will be created for each group when it exceeds the threshold. type: string index: anyOf: - items: {} type: array - type: boolean - type: number - type: object - type: string description: The indices to query. oneOf: - items: minLength: 1 type: string minItems: 1 type: array - not: {} searchConfiguration: anyOf: - items: {} type: array - type: boolean - type: number - type: object - type: string description: The query definition, which uses KQL or Lucene to fetch the documents from Elasticsearch. oneOf: - additionalProperties: true type: object properties: {} - not: {} searchType: default: esQuery description: 'The type of query For example: `esQuery` for Elasticsearch Query DSL or `esqlQuery` for Elasticsearch Query Language (ES|QL).' enum: - searchSource - esQuery - esqlQuery type: string size: description: The number of documents to pass to the configured actions when the threshold condition is met. maximum: 10000 minimum: 0 type: number sourceFields: description: The sourceFields param is ignored. items: additionalProperties: false type: object properties: label: type: string searchPath: type: string required: - label - searchPath maxItems: 5 type: array termField: anyOf: - minLength: 1 type: string - items: type: string maxItems: 4 minItems: 2 type: array description: The names of up to four fields that are used for grouping the aggregation. This property is required when `groupBy` is `top`. termSize: description: This property is required when `groupBy` is `top`. It specifies the number of groups to check against the threshold and therefore limits the number of alerts on high cardinality fields. minimum: 1 type: number threshold: items: description: The threshold value that is used with the `thresholdComparator`. If the `thresholdComparator` is `between` or `notBetween`, you must specify the boundary values. type: number maxItems: 2 minItems: 1 type: array thresholdComparator: description: 'The comparison function for the threshold. For example: greater than, less than, greater than or equal to, between, or not between.' enum: - '>' - < - '>=' - <= - between - notBetween type: string timeField: anyOf: - items: {} type: array - type: boolean - type: number - type: object - type: string description: The field that is used to calculate the time window. oneOf: - minLength: 1 type: string - minLength: 1 type: string timeWindowSize: description: The size of the time window (in `timeWindowUnit` units), which determines how far back to search for documents. Generally it should be a value higher than the rule check interval to avoid gaps in detection. minimum: 1 type: number timeWindowUnit: description: 'The type of units for the time window. For example: seconds, minutes, hours, or days.' type: string required: - size - timeWindowSize - timeWindowUnit - threshold - thresholdComparator - timeField - searchConfiguration - esQuery - index - esqlQuery title: ES Query Rule Params type: object rule_type_id: enum: - .es-query type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: ES query type: object Kibana_HTTP_APIs_apm-anomaly-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: false description: The parameters for the APM anomaly rule. These parameters are appropriate when `rule_type_id` is `apm.anomaly"`. properties: anomalyDetectorTypes: description: The types of anomalies that are detected. For example, detect abnormal latency, throughput, failed transaction rates, or low transaction count. items: enum: - txLatency - txThroughput - txFailureRate - txLowCount type: string minItems: 1 type: array anomalySeverityType: description: 'The severity of anomalies that result in an alert: critical, major, minor, or warning.' enum: - critical - major - minor - warning type: string environment: description: The environment from APM. type: string serviceName: description: The service name from APM. type: string transactionType: description: The transaction type from APM. type: string windowSize: description: The size of the time window (in `windowUnit` units), which determines how far back to search for documents. Generally it should be a value higher than the rule check interval to avoid gaps in detection. type: number windowUnit: description: 'The type of units for the time window: minutes, hours, or days.' type: string required: - windowSize - windowUnit - environment - anomalySeverityType title: APM Anomaly Rule Params type: object rule_type_id: enum: - apm.anomaly type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: APM anomaly type: object Kibana_HTTP_APIs_new_rule_action_alerts_filter: additionalProperties: false description: Conditions that affect whether the action runs. If you specify multiple conditions, all conditions must be met for the action to run. For example, if an alert occurs within the specified time frame and matches the query, the action runs. properties: query: $ref: '#/components/schemas/Kibana_HTTP_APIs_alerts_filter_query' timeframe: additionalProperties: false description: Defines a period that limits whether the action runs. type: object properties: days: description: Defines the days of the week that the action can run, represented as an array of numbers. For example, `1` represents Monday. An empty array is equivalent to specifying all the days of the week. items: enum: - 1 - 2 - 3 - 4 - 5 - 6 - 7 type: integer type: array hours: additionalProperties: false description: Defines the range of time in a day that the action can run. If the `start` value is `00:00` and the `end` value is `24:00`, actions be generated all day. type: object properties: end: description: The end of the time frame, in 24-hour notation (`hh:mm`). type: string start: description: The start of the time frame, in 24-hour notation (`hh:mm`). type: string required: - start - end timezone: description: The ISO time zone for the `hours` values. Values such as `UTC` and `UTC+1` also work but lack built-in support for daylight savings time and are not recommended. type: string required: - days - hours - timezone title: new_rule_action_alerts_filter type: object Kibana_HTTP_APIs_monitoring-shard-size-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: true description: The parameters for the large shard size rule. These parameters are appropriate when `rule_type_id` is `monitoring_shard_size`. properties: duration: type: string filterQuery: type: string filterQueryText: type: string indexPattern: type: string limit: type: string threshold: type: number required: - duration - indexPattern title: Large Shard Size Rule Params type: object rule_type_id: enum: - monitoring_shard_size type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: Large shard size type: object Kibana_HTTP_APIs_monitoring-alert-thread-pool-search-rejections-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: false description: The parameters for the thread pool search rejections rule. These parameters are appropriate when `rule_type_id` is `monitoring_alert_thread_pool_search_rejections`. properties: duration: type: string filterQuery: type: string filterQueryText: type: string threshold: type: number required: - duration title: Thread Pool Search Rejections Rule Params type: object rule_type_id: enum: - monitoring_alert_thread_pool_search_rejections type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: Thread pool search rejections type: object Kibana_HTTP_APIs_monitoring-alert-kibana-version-mismatch-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: true description: The parameters for the Kibana version mismatch rule. These parameters are appropriate when `rule_type_id` is `monitoring_alert_kibana_version_mismatch`. properties: duration: type: string filterQuery: type: string filterQueryText: type: string limit: type: string threshold: type: number required: - duration title: Kibana Version Mismatch Rule Params type: object rule_type_id: enum: - monitoring_alert_kibana_version_mismatch type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: Kibana version mismatch type: object Kibana_HTTP_APIs_xpack-uptime-alerts-monitorstatus-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: false description: The parameters for the uptime monitor status rule. These parameters are appropriate when `rule_type_id` is `xpack.uptime.alerts.monitorStatus`. properties: availability: additionalProperties: false type: object properties: range: type: number rangeUnit: type: string threshold: type: string required: - range - rangeUnit - threshold filters: anyOf: - additionalProperties: false type: object properties: monitor.type: items: type: string type: array observer.geo.name: items: type: string type: array tags: items: type: string type: array url.port: items: type: string type: array - type: string isAutoGenerated: type: boolean locations: items: type: string type: array numTimes: type: number search: type: string shouldCheckAvailability: type: boolean shouldCheckStatus: type: boolean stackVersion: type: string timerange: additionalProperties: false type: object properties: from: type: string to: type: string required: - from - to timerangeCount: type: number timerangeUnit: type: string version: type: number required: - numTimes - shouldCheckStatus - shouldCheckAvailability title: Uptime Monitor Status Rule Params type: object rule_type_id: enum: - xpack.uptime.alerts.monitorStatus type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: Uptime monitor status type: object Kibana_HTTP_APIs_monitoring-alert-disk-usage-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: true description: The parameters for the disk usage rule. These parameters are appropriate when `rule_type_id` is `monitoring_alert_disk_usage`. properties: duration: type: string filterQuery: type: string filterQueryText: type: string limit: type: string threshold: type: number required: - duration title: Disk Usage Rule Params type: object rule_type_id: enum: - monitoring_alert_disk_usage type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: Disk usage type: object Kibana_HTTP_APIs_monitoring-alert-logstash-version-mismatch-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: true description: The parameters for the logstash version mismatch rule. These parameters are appropriate when `rule_type_id` is `monitoring_alert_logstash_version_mismatch`. properties: duration: type: string filterQuery: type: string filterQueryText: type: string limit: type: string threshold: type: number required: - duration title: Logstash Version Mismatch Rule Params type: object rule_type_id: enum: - monitoring_alert_logstash_version_mismatch type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: Logstash version mismatch type: object Kibana_HTTP_APIs_transform-health-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: false description: The parameters for the transform health rule. These parameters are appropriate when `rule_type_id` is `transform_health`. properties: excludeTransforms: default: null items: type: string type: - array - 'null' includeTransforms: items: type: string type: array testsConfig: additionalProperties: false default: null type: - object - 'null' properties: errorMessages: additionalProperties: false default: null type: - object - 'null' properties: enabled: default: false type: boolean healthCheck: additionalProperties: false default: null type: - object - 'null' properties: enabled: default: true type: boolean notStarted: additionalProperties: false default: null type: - object - 'null' properties: enabled: default: true type: boolean required: - includeTransforms title: Transform Health Rule Params type: object rule_type_id: enum: - transform_health type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: Transform health type: object Kibana_HTTP_APIs_update_rule_action_alerts_filter: additionalProperties: false properties: query: $ref: '#/components/schemas/Kibana_HTTP_APIs_alerts_filter_query' timeframe: additionalProperties: false description: Defines a period that limits whether the action runs. type: object properties: days: description: Defines the days of the week that the action can run, represented as an array of numbers. For example, `1` represents Monday. An empty array is equivalent to specifying all the days of the week. items: enum: - 1 - 2 - 3 - 4 - 5 - 6 - 7 type: integer type: array hours: additionalProperties: false description: Defines the range of time in a day that the action can run. If the `start` value is `00:00` and the `end` value is `24:00`, actions be generated all day. type: object properties: end: description: The end of the time frame, in 24-hour notation (`hh:mm`). type: string start: description: The start of the time frame, in 24-hour notation (`hh:mm`). type: string required: - start - end timezone: description: The ISO time zone for the `hours` values. Values such as `UTC` and `UTC+1` also work but lack built-in support for daylight savings time and are not recommended. type: string required: - days - hours - timezone title: update_rule_action_alerts_filter type: object Kibana_HTTP_APIs_alerts_filter_query: additionalProperties: false properties: dsl: description: A filter written in Elasticsearch Query Domain Specific Language (DSL). type: string filters: description: A filter written in Elasticsearch Query Domain Specific Language (DSL) as defined in the `kbn-es-query` package. items: additionalProperties: false type: object properties: $state: additionalProperties: false type: object properties: store: description: A filter that can be applied to a specific application context or applied globally. enum: - appState - globalState type: string required: - store meta: additionalProperties: description: An object with fields such as "controlledBy", "disabled", "field", "group", "index", "isMultiIndex", "key", "negate", "params", "type", "value" type: object query: additionalProperties: description: A query for the filter. type: object required: - meta type: array kql: description: A filter written in Kibana Query Language (KQL). type: string required: - kql - filters title: alerts_filter_query type: object Kibana_HTTP_APIs_xpack-synthetics-alerts-tls-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: false description: The parameters for the synthetics tls rule. These parameters are appropriate when `rule_type_id` is `xpack.synthetics.alerts.tls`. properties: browserResourceTypes: items: maxLength: 1024 type: string maxItems: 100 type: array certAgeThreshold: type: number certExpirationThreshold: type: number certOrigin: items: maxLength: 256 type: string maxItems: 100 type: array includeBrowserCerts: type: boolean issuers: items: maxLength: 4096 type: string maxItems: 1000 type: array kqlQuery: type: string locations: items: type: string type: array monitorIds: items: type: string type: array monitorTypes: items: type: string type: array projects: items: type: string type: array search: type: string tags: items: type: string type: array title: Synthetics TLS Rule Params type: object rule_type_id: enum: - xpack.synthetics.alerts.tls type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: Synthetics TLS type: object Kibana_HTTP_APIs_monitoring-alert-thread-pool-write-rejections-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: false description: The parameters for the thread pool write rejections rule. These parameters are appropriate when `rule_type_id` is `monitoring_alert_thread_pool_write_rejections`. properties: duration: type: string filterQuery: type: string filterQueryText: type: string threshold: type: number required: - duration title: Thread Pool Write Rejections Rule Params type: object rule_type_id: enum: - monitoring_alert_thread_pool_write_rejections type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: Thread pool write rejections type: object Kibana_HTTP_APIs_apm-transaction-error-rate-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: false description: The parameters for the transaction error rate rule. These parameters are appropriate when `rule_type_id` is `apm.transaction_error_rate`. properties: environment: type: string groupBy: items: type: string type: array searchConfiguration: additionalProperties: false type: object properties: query: additionalProperties: false type: object properties: language: type: string query: anyOf: - type: string - additionalProperties: {} type: object required: - query - language required: - query serviceName: type: string threshold: type: number transactionName: type: string transactionType: type: string useKqlFilter: type: boolean windowSize: type: number windowUnit: type: string required: - windowSize - windowUnit - threshold - environment title: Transaction Error Rate Rule Params type: object rule_type_id: enum: - apm.transaction_error_rate type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: Transaction error rate type: object Kibana_HTTP_APIs_xpack-uptime-alerts-durationanomaly-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: false description: The parameters for the uptime duration anomaly rule. These parameters are appropriate when `rule_type_id` is `xpack.uptime.alerts.durationAnomaly`. properties: monitorId: type: string severity: type: number stackVersion: type: string required: - monitorId - severity title: Uptime Duration Anomaly Rule Params type: object rule_type_id: enum: - xpack.uptime.alerts.durationAnomaly type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: Uptime duration anomaly type: object Kibana_HTTP_APIs_geo-containment-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: false description: The parameters for the geo containment rule. These parameters are appropriate when `rule_type_id` is `.geo-containment`. properties: boundaryGeoField: minLength: 1 type: string boundaryIndexId: minLength: 1 type: string boundaryIndexQuery: {} boundaryIndexTitle: minLength: 1 type: string boundaryNameField: minLength: 1 type: string boundaryType: minLength: 1 type: string dateField: minLength: 1 type: string entity: minLength: 1 type: string geoField: minLength: 1 type: string index: minLength: 1 type: string indexId: minLength: 1 type: string indexQuery: {} required: - index - indexId - geoField - entity - dateField - boundaryType - boundaryIndexTitle - boundaryIndexId - boundaryGeoField - indexQuery - boundaryIndexQuery title: Geo Containment Rule Params type: object rule_type_id: enum: - .geo-containment type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: Geo containment type: object Kibana_HTTP_APIs_monitoring-alert-nodes-changed-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: true description: The parameters for the nodes changed rule. These parameters are appropriate when `rule_type_id` is `monitoring_alert_nodes_changed`. properties: duration: type: string filterQuery: type: string filterQueryText: type: string limit: type: string threshold: type: number required: - duration title: Nodes Changed Rule Params type: object rule_type_id: enum: - monitoring_alert_nodes_changed type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: Nodes changed type: object Kibana_HTTP_APIs_monitoring-alert-cpu-usage-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: true description: The parameters for the CPU usage rule. These parameters are appropriate when `rule_type_id` is `monitoring_alert_cpu_usage`. properties: duration: type: string filterQuery: type: string filterQueryText: type: string limit: type: string threshold: type: number required: - duration title: CPU Usage Rule Params type: object rule_type_id: enum: - monitoring_alert_cpu_usage type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: CPU usage type: object Kibana_HTTP_APIs_metrics-alert-inventory-threshold-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: true description: The parameters for the metric inventory threshold rule. These parameters are appropriate when `rule_type_id` is `metrics.alert.inventory.threshold`. properties: alertOnNoData: type: boolean criteria: items: additionalProperties: false type: object properties: comparator: type: string customMetric: additionalProperties: false type: object properties: aggregation: type: string field: type: string id: type: string label: type: string type: enum: - custom type: string required: - type - id - field - aggregation metric: type: string threshold: items: type: number type: array timeSize: type: number timeUnit: type: string warningComparator: type: string warningThreshold: items: type: number type: array required: - threshold - comparator - timeUnit - timeSize - metric type: array filterQuery: type: string nodeType: type: string schema: type: string sourceId: type: string required: - criteria - nodeType - sourceId title: Metric Inventory Threshold Rule Params type: object rule_type_id: enum: - metrics.alert.inventory.threshold type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: Metric inventory threshold type: object Alerting_401_response: properties: error: enum: - Unauthorized example: Unauthorized type: string message: type: string statusCode: enum: - 401 example: 401 type: integer title: Unsuccessful rule API response type: object Kibana_HTTP_APIs_apm-error-rate-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: false description: The parameters for the error count rule. These parameters are appropriate when `rule_type_id` is `apm.error_rate`. properties: environment: description: Filter the errors coming from your application to apply the rule to a specific environment. type: string errorGroupingKey: description: Filter the errors coming from your application to apply the rule to a specific error grouping key, which is a hash of the stack trace and other properties. type: string groupBy: items: description: Perform a composite aggregation against the selected fields. When any of these groups match the selected rule conditions, an alert is triggered per group. type: string type: array searchConfiguration: additionalProperties: false type: object properties: query: additionalProperties: false type: object properties: language: type: string query: anyOf: - type: string - additionalProperties: {} type: object required: - query - language required: - query serviceName: description: Filter the errors coming from your application to apply the rule to a specific service. type: string threshold: description: The number of errors, which is the threshold for alerts. type: number useKqlFilter: description: A filter in Kibana Query Language (KQL) that limits the scope of the rule. type: boolean windowSize: description: The time frame in which the errors must occur (in `windowUnit` units). Generally it should be a value higher than the rule check interval to avoid gaps in detection. type: number windowUnit: description: 'The type of units for the time window: minutes, hours, or days.' type: string required: - windowSize - windowUnit - threshold - environment title: Error Count Rule Params type: object rule_type_id: enum: - apm.error_rate type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: Error rate type: object Kibana_HTTP_APIs_monitoring-alert-cluster-health-create-rule-body-alerting: additionalProperties: false properties: actions: default: [] items: $ref: '#/components/schemas/Kibana_HTTP_APIs_new_rule_action' type: array alert_delay: additionalProperties: false description: Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions. type: object properties: active: description: The number of consecutive runs that must meet the rule conditions. type: number required: - active artifacts: additionalProperties: false type: object properties: dashboards: items: additionalProperties: false type: object properties: id: type: string required: - id maxItems: 10 type: array investigation_guide: additionalProperties: false type: object properties: blob: maxLength: 10000 type: string required: - blob consumer: description: 'The name of the application or feature that owns the rule. For example: `alerts`, `apm`, `discover`, `infrastructure`, `logs`, `metrics`, `ml`, `monitoring`, `securitySolution`, `siem`, `stackAlerts`, or `uptime`.' type: string enabled: default: true description: Indicates whether you want the rule to run on an interval basis after it is created. type: boolean flapping: allOf: - $ref: '#/components/schemas/Kibana_HTTP_APIs_rule_flapping' name: description: The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule. type: string notify_when: description: 'Indicates how frequently rule actions are triggered. Valid values include: `onActionGroupChange`: Actions run when the alert status changes; `onActiveAlert`: Actions run when the alert becomes active and at each check interval while the rule conditions are met; `onThrottleInterval`: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify `notify_when` at both the rule and action level. The recommended approach is to set it for each action individually. If you set `notify_when` at the rule level and then edit the rule, it will automatically be converted to action-specific values.' enum: - onActionGroupChange - onActiveAlert - onThrottleInterval - null type: - string - 'null' params: additionalProperties: true description: The parameters for the cluster health rule. These parameters are appropriate when `rule_type_id` is `monitoring_alert_cluster_health`. properties: duration: type: string filterQuery: type: string filterQueryText: type: string limit: type: string threshold: type: number required: - duration title: Cluster Health Rule Params type: object rule_type_id: enum: - monitoring_alert_cluster_health type: string schedule: additionalProperties: false description: The check interval, which specifies how frequently the rule conditions are checked. type: object properties: interval: description: The interval is specified in seconds, minutes, hours, or days. type: string required: - interval tags: default: [] description: The tags for the rule. items: type: string type: array template_id: description: The identifier for the rule template this rule was created from, when known. maxLength: 1024 type: string throttle: description: Use the `throttle` property in the action `frequency` object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values. type: - string - 'null' required: - name - consumer - schedule - rule_type_id - params title: Cluster health type: object Kibana_HTTP_APIs_update_rule_action: additionalProperties: false description: An action that runs under defined conditions. properties: alerts_filter: $ref: '#/components/schemas/Kibana_HTTP_APIs_update_rule_action_alerts_filter' frequency: $ref: '#/components/schemas/Kibana_HTTP_APIs_update_rule_action_frequency' group: description: The group name, which affects when the action runs (for example, when the threshold is met or when the alert is recovered). Each rule type has a list of valid action group names. If you don't need to group actions, set to `default`. type: string id: description: The identifier for the connector saved object. type: string params: additionalProperties: {} default: {} description: The parameters for the action, which are sent to the connector. The `params` are handled as Mustache templates and passed a default set of context. type: object use_alert_data_for_template: description: Indicates whether to use alert data as a template. type: boolean uuid: description: A universally unique identifier (UUID) for the action. type: string required: - id title: update_rule_action type: object examples: Alerting_get_health_response: summary: Retrieve information about the health of the alerting framework. value: alerting_framework_health: decryption_health: status: ok timestamp: '2023-01-13T01:28:00.280Z' execution_health: status: ok timestamp: '2023-01-13T01:28:00.280Z' read_health: status: ok timestamp: '2023-01-13T01:28:00.280Z' has_permanent_encryption_key: true is_sufficiently_secure: true Alerting_401_health_response: summary: Unauthorized response for the get alerting health API. value: error: Unauthorized message: '[security_exception] missing authentication credentials for REST request' statusCode: 401 Alerting_get_rule_types_response: summary: Retrieve rule types associated with Kibana machine learning features value: - action_groups: - id: anomaly_score_match name: Anomaly score matched the condition - id: recovered name: Recovered action_variables: context: - description: The bucket timestamp of the anomaly name: timestamp - description: The bucket time of the anomaly in ISO8601 format name: timestampIso8601 - description: List of job IDs that triggered the alert name: jobIds - description: Alert info message name: message - description: Indicate if top hits contain interim results name: isInterim - description: Anomaly score at the time of the notification action name: score - description: Top records name: topRecords - description: Top influencers name: topInfluencers - description: URL to open in the Anomaly Explorer name: anomalyExplorerUrl useWithTripleBracesInTemplates: true params: [] state: [] alerts: context: ml.anomaly-detection mappings: fieldMap: kibana.alert.anomaly_score: array: false type: double required: false kibana.alert.anomaly_timestamp: array: false type: date required: false kibana.alert.is_interim: array: false type: boolean required: false kibana.alert.job_id: array: false type: keyword required: true kibana.alert.top_influencers: array: true dynamic: false type: object properties: influencer_field_name: type: keyword influencer_field_value: type: keyword influencer_score: type: double initial_influencer_score: type: double is_interim: type: boolean job_id: type: keyword timestamp: type: date required: false kibana.alert.top_records: array: true dynamic: false type: object properties: actual: type: double by_field_name: type: keyword by_field_value: type: keyword detector_index: type: integer field_name: type: keyword function: type: keyword initial_record_score: type: double is_interim: type: boolean job_id: type: keyword over_field_name: type: keyword over_field_value: type: keyword partition_field_name: type: keyword partition_field_value: type: keyword record_score: type: double timestamp: type: date typical: type: double required: false shouldWrite: true authorized_consumers: alerts: all: true read: true apm: all: true read: true discover: all: true read: true infrastructure: all: true read: true logs: all: true read: true ml: all: true read: true monitoring: all: true read: true siem: all: true read: true slo: all: true read: true stackAlerts: all: true read: true uptime: all: true read: true category: management default_action_group_id: anomaly_score_match does_set_recovery_context: true enabled_in_license: true has_alerts_mappings: true has_fields_for_a_a_d: true id: xpack.ml.anomaly_detection_alert is_exportable: true minimum_license_required: platinum name: Anomaly detection alert producer: ml recovery_action_group: id: recovered name: Recovered rule_task_timeout: 5m - action_groups: - id: anomaly_detection_realtime_issue name: Issue detected - id: recovered name: Recovered action_variables: context: - description: Results of the rule execution name: results - description: Alert info message name: message params: [] state: [] authorized_consumers: alerts: all: true read: true apm: all: true read: true discover: all: true read: true infrastructure: all: true read: true logs: all: true read: true ml: all: true read: true monitoring: all: true read: true siem: all: true read: true slo: all: true read: true stackAlerts: all: true read: true uptime: all: true read: true category: management default_action_group_id: anomaly_detection_realtime_issue does_set_recovery_context: true enabled_in_license: true has_alerts_mappings: false has_fields_for_a_a_d: false id: xpack.ml.anomaly_detection_jobs_health is_exportable: true minimum_license_required: platinum name: Anomaly detection jobs health producer: ml recovery_action_group: id: recovered name: Recovered rule_task_timeout: 5m Alerting_401_rule_types_response: summary: Unauthorized response for the get rule types API. value: error: Unauthorized message: '[security_exception] missing authentication credentials for REST request' statusCode: 401 securitySchemes: apiKeyAuth: description: 'These APIs use key-based authentication. You must create an API key and use the encoded value in the request header. For example: `Authorization: ApiKey base64AccessApiKey` ' in: header name: Authorization type: apiKey basicAuth: scheme: basic type: http x-topics: - title: Kibana spaces content: "Spaces enable you to organize your dashboards and other saved objects into meaningful categories.\nYou can use the default space or create your own spaces.\n\nTo run APIs in non-default spaces, you must add `s/{space_id}/` to the path.\nFor example:\n\n```bash\ncurl -X GET \"http://${KIBANA_URL}/s/marketing/api/data_views\" \\\n -H \"Authorization: ApiKey ${API_KEY}\"\n```\n\nIf you use the Kibana console to send API requests, it automatically adds the appropriate space identifier.\n\nTo learn more, check out [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces).\n"