Spaces method and path for this operation:
Refer to Spaces for more information.
[Required authorization] Route required privileges: manage_alerting-v2-rules.
Body
-
Optional objects attached to the rule, such as a runbook or a dashboard. Each item has
id,type, anddata. The shape ofdatadepends ontype. For example, arunbookusescontentand adashboardusesdashboard_id. Known types are validated against that shape. Unknown types are stored whenid,type, anddataare present.Not more than
100elements. -
Grouping configuration.
Additional properties are NOT allowed.
-
Additional properties are NOT allowed.
- no_data_strategy
string | null How the rule behaves when it finds no data for a group. If omitted, the existing value is kept. Set to
nullto clear it (those runs are then ignored). If you setlast_known_statusorrecover, a standalone query (query.format: standalone) must includequery.no_data. A composed query (query.format: composed) usesquery.baseto detect whether data is present. Theemitvalue is not accepted when creating or updating rules.Any of: Keeps the alert's last status when the rule finds no data.
Value is
last_known_status.Not accepted when creating or updating rules. Do not send this value.
Value is
emit.Marks the alert
inactivethe first time the rule finds no data for the alert.Value is
recover.Ignores runs where the rule finds no data.
Value is
none. - recovery_strategy
string | null The condition that marks an alert recovered. If omitted, the existing value is kept. Set to
nullto clear it (recovery is then disabled). Set tono_breachto recover when the breach query stops returning matches. Set toqueryonly when you also providequery.recovery. Withnone, the alert staysactive, even after the breach query stops returning matches.state_transition.recovering_countandrecovering_timeframerequire an explicitrecovery_strategyother thannone.Any of: Recovers an alert when the breach query no longer returns matches.
Value is
no_breach.Recovers an alert when a separate recovery query matches. Requires
query.recovery.Value is
query.The rule never marks an alert as
recovered, even after the breach query stops returning matches.Value is
none. -
Additional properties are NOT allowed.
-
Document field used as the event time when applying the lookback window. If omitted, the existing value is kept.
Minimum length is
1, maximum length is128. -
The current version of the rule, used for optimistic concurrency control.
Minimum length is
1, maximum length is256.
Responses
-
Returns the updated rule.
-
Indicates an invalid schema or parameters.
-
Indicates the request was not authenticated.
-
Indicates the user does not have the required privileges to perform the request.
-
Indicates a rule with the given ID does not exist.
-
Indicates the rule was concurrently updated by another caller.
-
Indicates an unexpected server-side error.
-
Indicates the alerting engine is disabled by the
alerting:v2:enabledadvanced setting.
curl \
--request PATCH 'https://localhost:5601/api/alerting/v2/rules/{id}' \
--header "Authorization: $API_KEY" \
--header "Content-Type: application/json" \
--header "kbn-xsrf: true" \
--data '{
"metadata": {
"description": "Updated description.",
"name": "Host CPU high (updated)"
},
"version": "WzAsMV0="
}'
{
"metadata": {
"description": "Updated description.",
"name": "Host CPU high (updated)"
},
"version": "WzAsMV0="
}
{
"created_at": "2026-01-15T12:00:00.000Z",
"created_by": "elastic",
"enabled": true,
"grouping": {
"fields": [
"host.name"
]
},
"id": "rule-1",
"kind": "alert",
"metadata": {
"description": "Updated description.",
"name": "Host CPU high (updated)",
"tags": [
"production",
"infra"
],
"version": 1
},
"query": {
"breach": {
"query": "FROM metrics-* | WHERE host.cpu.usage > 0.9 | STATS avg_cpu = AVG(host.cpu.usage) BY host.name"
},
"format": "standalone"
},
"recovery_strategy": "no_breach",
"schedule": {
"every": "1m",
"lookback": "5m"
},
"state_transition": {
"pending_count": 1,
"recovering_count": 1
},
"time_field": "@timestamp",
"updated_at": "2026-01-15T12:00:00.000Z",
"updated_by": "elastic",
"version": "WzAsMV0="
}
{
"code": "BAD_REQUEST",
"details": {
"errors": {
"unknownField": [
"Unrecognized key"
]
}
},
"error": "Bad Request",
"message": "Unrecognized key(s) in object: 'unknownField'"
}
{
"code": "UNAUTHORIZED",
"error": "Unauthorized",
"message": "Authentication required to access this API."
}
{
"code": "FORBIDDEN",
"error": "Forbidden",
"message": "The current user does not have the required privileges for this request."
}
{
"code": "RULE_NOT_FOUND",
"details": {
"rule_id": "rule-1"
},
"error": "Not Found",
"message": "Rule with id \"rule-1\" not found"
}
{
"code": "RULE_VERSION_CONFLICT",
"details": {
"rule_id": "rule-1"
},
"error": "Conflict",
"message": "Rule with id \"rule-1\" has already been updated by another user"
}
{
"code": "INTERNAL_SERVER_ERROR",
"error": "Internal Server Error",
"message": "An unexpected error occurred."
}
{
"code": "ALERTING_DISABLED",
"error": "Service Unavailable",
"message": "Alerting is disabled."
}