Spaces method and path for this operation:
Refer to Spaces for more information.
[Required authorization] Route required privileges: manage_alerting-v2-rules.
Path parameters
-
The identifier for the rule. Chosen at creation and permanent — it cannot be changed afterwards. Re-using the id of a deleted resource is allowed but discouraged: execution history, change history, and alert episodes recorded under that id are retained and are attributed to the new resource. Ids appear in URLs and logs, so keep them free of sensitive data.
Minimum length is
1, maximum length is150. Format should match the following pattern:^[a-zA-Z0-9_-]+$.
Body
-
Optional objects attached to the rule, such as a runbook or a dashboard. Each item has
id,type, anddata. The shape ofdatadepends ontype. For example, arunbookusescontentand adashboardusesdashboard_id. Known types are validated against that shape. Unknown types are stored whenid,type, anddataare present.Not more than
100elements. -
Grouping configuration.
Additional properties are NOT allowed.
-
Additional properties are NOT allowed.
-
ES|QL query the rule evaluates.
baseis required.breachis an optional clause appended to it.Additional properties are NOT allowed.
-
Additional properties are NOT allowed.
-
Specifies how many consecutive matches, or how long a condition must hold, before an alert becomes
activeorinactive. Allowed only whenkindisalert.Additional properties are NOT allowed.
-
Document field Kibana uses with
schedule.lookbackto time-filterquery.base. If omitted, the existing value is kept.Minimum length is
1, maximum length is256.
Responses
-
Returns the updated rule.
-
Indicates an invalid schema or parameters.
-
Indicates the request was not authenticated.
-
Indicates the user does not have the required privileges to perform the request.
-
Indicates a rule with the given ID does not exist.
-
Indicates the rule was concurrently updated by another caller.
-
Indicates an unexpected server-side error.
-
Indicates the alerting engine is disabled by the
alerting:v2:enabledadvanced setting.
curl \
--request PATCH 'https://<KIBANA_URL>/api/alerting/v2/rules/{id}' \
--header "Authorization: $API_KEY" \
--header "Content-Type: application/json" \
--header "kbn-xsrf: true" \
--data '{
"metadata": {
"description": "Updated description.",
"name": "Host CPU high (updated)"
}
}'
{
"metadata": {
"description": "Updated description.",
"name": "Host CPU high (updated)"
}
}
{
"created_at": "2026-01-15T12:00:00.000Z",
"created_by": {
"profile_uid": "u_elastic_0"
},
"enabled": true,
"grouping": {
"fields": [
"host.name"
]
},
"id": "rule-1",
"kind": "alert",
"metadata": {
"description": "Updated description.",
"name": "Host CPU high (updated)",
"routing_tags": [
"sre-oncall"
],
"tags": [
"production",
"infra"
]
},
"no_data": {
"strategy": "keep_last"
},
"query": {
"base": "FROM metrics-* | STATS avg_cpu = AVG(host.cpu.usage) BY host.name",
"breach": {
"segment": "WHERE avg_cpu > 0.9"
}
},
"recovery": {
"strategy": "no_breach"
},
"schedule": {
"every": "1m",
"lookback": "5m"
},
"state_transition": {
"pending": {
"count": 1
},
"recovering": {
"count": 1
}
},
"time_field": "@timestamp",
"updated_at": "2026-01-15T12:00:00.000Z",
"updated_by": {
"profile_uid": "u_elastic_0"
},
"version": 1
}
{
"code": "BAD_REQUEST",
"details": {
"errors": {
"unknownField": [
"Unrecognized key"
]
}
},
"error": "Bad Request",
"message": "Unrecognized key(s) in object: 'unknownField'"
}
{
"code": "UNAUTHORIZED",
"error": "Unauthorized",
"message": "Authentication required to access this API."
}
{
"code": "FORBIDDEN",
"error": "Forbidden",
"message": "The current user does not have the required privileges for this request."
}
{
"code": "RULE_NOT_FOUND",
"details": {
"rule_id": "rule-1"
},
"error": "Not Found",
"message": "Rule with id \"rule-1\" not found"
}
{
"code": "RULE_VERSION_CONFLICT",
"details": {
"rule_id": "rule-1"
},
"error": "Conflict",
"message": "Rule with id \"rule-1\" has already been updated by another user"
}
{
"code": "INTERNAL_SERVER_ERROR",
"error": "Internal Server Error",
"message": "An unexpected error occurred."
}
{
"code": "ALERTING_DISABLED",
"error": "Service Unavailable",
"message": "Alerting is disabled."
}