Spaces method and path for this operation:
Refer to Spaces for more information.
Creates a rule with a server-generated identifier. To create or replace a rule with a client-supplied identifier, use PUT /api/alerting/v2/rules/{id}/.
[Required authorization] Route required privileges: manage_alerting-v2-rules.
Body
-
Optional objects attached to the rule, such as a runbook or a dashboard. Each item has
id,type, anddata. The shape ofdatadepends ontype. For example, arunbookusescontentand adashboardusesdashboard_id. Known types are validated against that shape. Unknown types are stored whenid,type, anddataare present.Not more than
100elements. -
Grouping configuration.
Additional properties are NOT allowed.
- kind
string Required Whether the rule creates alerts (
alert) or only stores matching events (signal). -
Rule metadata.
Additional properties are NOT allowed.
- no_data_strategy
string How the rule behaves when it finds no data for a group. If you omit this field or set it to
none, those runs are ignored. If you setlast_known_statusorrecover, a standalone query (query.format: standalone) must includequery.no_data. A composed query (query.format: composed) usesquery.baseto detect whether data is present. Theemitvalue is not accepted when creating or updating rules.Any of: Keeps the alert's last status when the rule finds no data.
Value is
last_known_status.Not accepted when creating or updating rules. Do not send this value.
Value is
emit.Marks the alert
inactivethe first time the rule finds no data for the alert.Value is
recover.Ignores runs where the rule finds no data.
Value is
none. - recovery_strategy
string The condition that marks an alert recovered. If omitted or set to
none, recovery is disabled: the alert staysactiveeven after the breach query stops returning matches, andstate_transition.recovering_count/recovering_timeframeare not allowed. Set tono_breachto recover when the breach query stops returning matches. Set toqueryonly when you also providequery.recovery.Any of: Recovers an alert when the breach query no longer returns matches.
Value is
no_breach.Recovers an alert when a separate recovery query matches. Requires
query.recovery.Value is
query.The rule never marks an alert as
recovered, even after the breach query stops returning matches.Value is
none. -
Execution schedule configuration.
Additional properties are NOT allowed.
-
Consecutive-match or time requirements before an alert becomes
activeorinactive. Applies only whenkindisalert.Additional properties are NOT allowed.
-
Document field used as the event time when applying the lookback window. Defaults to
@timestamp.Minimum length is
1, maximum length is128. Default value is@timestamp.
Responses
-
Returns the newly created rule.
-
Indicates an invalid schema or parameters.
-
Indicates the request was not authenticated.
-
Indicates the user does not have the required privileges to perform the request.
-
Indicates an unexpected server-side error.
-
Indicates the alerting engine is disabled by the
alerting:v2:enabledadvanced setting.
curl \
--request POST 'https://localhost:5601/api/alerting/v2/rules' \
--header "Authorization: $API_KEY" \
--header "Content-Type: application/json" \
--header "kbn-xsrf: true" \
--data '{
"grouping": {
"fields": [
"host.name"
]
},
"kind": "alert",
"metadata": {
"description": "Alerts when average CPU usage exceeds a threshold.",
"name": "Host CPU high",
"tags": [
"production",
"infra"
]
},
"query": {
"breach": {
"query": "FROM metrics-* | WHERE host.cpu.usage > 0.9 | STATS avg_cpu = AVG(host.cpu.usage) BY host.name"
},
"format": "standalone"
},
"recovery_strategy": "no_breach",
"schedule": {
"every": "1m",
"lookback": "5m"
},
"state_transition": {
"pending_count": 1,
"recovering_count": 1
},
"time_field": "@timestamp"
}'
{
"grouping": {
"fields": [
"host.name"
]
},
"kind": "alert",
"metadata": {
"description": "Alerts when average CPU usage exceeds a threshold.",
"name": "Host CPU high",
"tags": [
"production",
"infra"
]
},
"query": {
"breach": {
"query": "FROM metrics-* | WHERE host.cpu.usage > 0.9 | STATS avg_cpu = AVG(host.cpu.usage) BY host.name"
},
"format": "standalone"
},
"recovery_strategy": "no_breach",
"schedule": {
"every": "1m",
"lookback": "5m"
},
"state_transition": {
"pending_count": 1,
"recovering_count": 1
},
"time_field": "@timestamp"
}
{
"created_at": "2026-01-15T12:00:00.000Z",
"created_by": "elastic",
"enabled": true,
"grouping": {
"fields": [
"host.name"
]
},
"id": "rule-1",
"kind": "alert",
"metadata": {
"description": "Alerts when average CPU usage exceeds a threshold.",
"name": "Host CPU high",
"tags": [
"production",
"infra"
],
"version": 1
},
"query": {
"breach": {
"query": "FROM metrics-* | WHERE host.cpu.usage > 0.9 | STATS avg_cpu = AVG(host.cpu.usage) BY host.name"
},
"format": "standalone"
},
"recovery_strategy": "no_breach",
"schedule": {
"every": "1m",
"lookback": "5m"
},
"state_transition": {
"pending_count": 1,
"recovering_count": 1
},
"time_field": "@timestamp",
"updated_at": "2026-01-15T12:00:00.000Z",
"updated_by": "elastic",
"version": "WzAsMV0="
}
{
"code": "BAD_REQUEST",
"details": {
"errors": {
"metadata": [
"Required"
]
}
},
"error": "Bad Request",
"message": "metadata: Required"
}
{
"code": "UNAUTHORIZED",
"error": "Unauthorized",
"message": "Authentication required to access this API."
}
{
"code": "FORBIDDEN",
"error": "Forbidden",
"message": "The current user does not have the required privileges for this request."
}
{
"code": "INTERNAL_SERVER_ERROR",
"error": "Internal Server Error",
"message": "An unexpected error occurred."
}
{
"code": "ALERTING_DISABLED",
"error": "Service Unavailable",
"message": "Alerting is disabled."
}