The requested rules, in the same order as the requested ids.
Hide rules attributesShow rules attributesobject
artifacts
array[object]
Optional objects attached to the rule, such as a runbook or a dashboard. Each item has id, type, and data. The shape of data depends on type. For example, a runbook uses content and a dashboard uses dashboard_id. Known types are validated against that shape. Unknown types are stored when id, type, and data are present.
Creates an alert for each matching group and tracks it until it recovers. Use this when you want to detect a problem and notify or automate a response.
Value is alert.
Stores each match as a rule event you can query. Alerts are not created and notifications are not sent.
Identifies the rule builder that authored this rule (e.g. "threshold"). Absent for rules authored directly in ES|QL.
Maximum length is 64.
description
string
Human-readable description of the rule.
Maximum length is 1024.
name
stringRequired
Rule name (must be unique within the space).
Minimum length is 1, maximum length is 256.
owner
string
Owner of the rule.
Maximum length is 256.
tags
array[string]
Tags for categorization, e.g. ["production", "infra"].
At least 1 but not more than 20 elements. Minimum length of each is 1, maximum length of each is 128.
version
integerRequired
Monotonically increasing integer number representing a rule configuration version, incremented on every change. Used on generated rule events as rule.version.
Minimum value is 1, maximum value is 9007199254740991.
no_data_strategy
string
How the rule behaves when it finds no data for a group. If you omit this field or set it to none, those runs are ignored. If you set last_known_status or recover, a standalone query (query.format: standalone) must include query.no_data. A composed query (query.format: composed) uses query.base to detect whether data is present. The emit value is not accepted when creating or updating rules.
The condition that marks an alert recovered. If omitted or set to none, recovery is disabled: the alert stays active even after the breach query stops returning matches, and state_transition.recovering_count / recovering_timeframe are not allowed. Set to no_breach to recover when the breach query stops returning matches. Set to query only when you also provide query.recovery.
Stable error code you can branch on, for example INVALID_SCHEDULE or RULE_ALREADY_EXISTS.
details
object
Optional extra information about the error, for example field validation issues or the rule_id when that ID already exists.
Additional properties are allowed.
error
stringRequired
A short human-readable summary of the error category (e.g., "Not Found", "Bad Request"). Subject to change without notice. Do not parse or rely on its content.
message
stringRequired
A readable explanation of the error. The wording can change without notice. Do not parse this field.
Stable error code you can branch on, for example INVALID_SCHEDULE or RULE_ALREADY_EXISTS.
details
object
Optional extra information about the error, for example field validation issues or the rule_id when that ID already exists.
Additional properties are allowed.
error
stringRequired
A short human-readable summary of the error category (e.g., "Not Found", "Bad Request"). Subject to change without notice. Do not parse or rely on its content.
message
stringRequired
A readable explanation of the error. The wording can change without notice. Do not parse this field.
403
application/json
Indicates the user does not have the required privileges to perform the request.
Stable error code you can branch on, for example INVALID_SCHEDULE or RULE_ALREADY_EXISTS.
details
object
Optional extra information about the error, for example field validation issues or the rule_id when that ID already exists.
Additional properties are allowed.
error
stringRequired
A short human-readable summary of the error category (e.g., "Not Found", "Bad Request"). Subject to change without notice. Do not parse or rely on its content.
message
stringRequired
A readable explanation of the error. The wording can change without notice. Do not parse this field.
Stable error code you can branch on, for example INVALID_SCHEDULE or RULE_ALREADY_EXISTS.
details
object
Optional extra information about the error, for example field validation issues or the rule_id when that ID already exists.
Additional properties are allowed.
error
stringRequired
A short human-readable summary of the error category (e.g., "Not Found", "Bad Request"). Subject to change without notice. Do not parse or rely on its content.
message
stringRequired
A readable explanation of the error. The wording can change without notice. Do not parse this field.
Stable error code you can branch on, for example INVALID_SCHEDULE or RULE_ALREADY_EXISTS.
details
object
Optional extra information about the error, for example field validation issues or the rule_id when that ID already exists.
Additional properties are allowed.
error
stringRequired
A short human-readable summary of the error category (e.g., "Not Found", "Bad Request"). Subject to change without notice. Do not parse or rely on its content.
message
stringRequired
A readable explanation of the error. The wording can change without notice. Do not parse this field.
503
application/json
Indicates the alerting engine is disabled by the alerting:v2:enabled advanced setting.
Stable error code you can branch on, for example INVALID_SCHEDULE or RULE_ALREADY_EXISTS.
details
object
Optional extra information about the error, for example field validation issues or the rule_id when that ID already exists.
Additional properties are allowed.
error
stringRequired
A short human-readable summary of the error category (e.g., "Not Found", "Bad Request"). Subject to change without notice. Do not parse or rely on its content.
message
stringRequired
A readable explanation of the error. The wording can change without notice. Do not parse this field.