Spaces method and path for this operation:
Refer to Spaces for more information.
Creates a rule with a server-generated identifier. To create or replace a rule with a client-supplied identifier, use PUT /api/alerting/v2/rules/{id}/.
[Required authorization] Route required privileges: manage_alerting-v2-rules.
Body
-
Optional objects attached to the rule, such as a runbook or a dashboard. Each item has
id,type, anddata. The shape ofdatadepends ontype. For example, arunbookusescontentand adashboardusesdashboard_id. Known types are validated against that shape. Unknown types are stored whenid,type, anddataare present.Not more than
100elements. -
Grouping configuration.
Additional properties are NOT allowed.
- kind
string Required Whether the rule creates alerts (
alert) or only stores matching events (signal). -
Rule metadata.
Additional properties are NOT allowed.
-
ES|QL query the rule evaluates.
baseis required.breachis an optional clause appended to it.Additional properties are NOT allowed.
-
Execution schedule configuration.
Additional properties are NOT allowed.
-
Specifies how many consecutive matches, or how long a condition must hold, before an alert becomes
activeorinactive. Allowed only whenkindisalert.Additional properties are NOT allowed.
-
Document field Kibana uses with
schedule.lookbackto time-filterquery.base.Minimum length is
1, maximum length is256. Default value is@timestamp.
Responses
-
Returns the newly created rule.
-
Indicates an invalid schema or parameters.
-
Indicates the request was not authenticated.
-
Indicates the user does not have the required privileges to perform the request.
-
Indicates an unexpected server-side error.
-
Indicates the alerting engine is disabled by the
alerting:v2:enabledadvanced setting.
curl \
--request POST 'https://<KIBANA_URL>/api/alerting/v2/rules' \
--header "Authorization: $API_KEY" \
--header "Content-Type: application/json" \
--header "kbn-xsrf: true" \
--data '{
"grouping": {
"fields": [
"host.name"
]
},
"kind": "alert",
"metadata": {
"description": "Alerts when average CPU usage exceeds a threshold.",
"name": "Host CPU high",
"routing_tags": [
"sre-oncall"
],
"tags": [
"production",
"infra"
]
},
"no_data": {
"strategy": "keep_last"
},
"query": {
"base": "FROM metrics-* | STATS avg_cpu = AVG(host.cpu.usage) BY host.name",
"breach": {
"segment": "WHERE avg_cpu > 0.9"
}
},
"recovery": {
"strategy": "no_breach"
},
"schedule": {
"every": "1m",
"lookback": "5m"
},
"state_transition": {
"pending": {
"count": 1
},
"recovering": {
"count": 1
}
},
"time_field": "@timestamp"
}'
{
"grouping": {
"fields": [
"host.name"
]
},
"kind": "alert",
"metadata": {
"description": "Alerts when average CPU usage exceeds a threshold.",
"name": "Host CPU high",
"routing_tags": [
"sre-oncall"
],
"tags": [
"production",
"infra"
]
},
"no_data": {
"strategy": "keep_last"
},
"query": {
"base": "FROM metrics-* | STATS avg_cpu = AVG(host.cpu.usage) BY host.name",
"breach": {
"segment": "WHERE avg_cpu > 0.9"
}
},
"recovery": {
"strategy": "no_breach"
},
"schedule": {
"every": "1m",
"lookback": "5m"
},
"state_transition": {
"pending": {
"count": 1
},
"recovering": {
"count": 1
}
},
"time_field": "@timestamp"
}
{
"created_at": "2026-01-15T12:00:00.000Z",
"created_by": {
"profile_uid": "u_elastic_0"
},
"enabled": true,
"grouping": {
"fields": [
"host.name"
]
},
"id": "rule-1",
"kind": "alert",
"metadata": {
"description": "Alerts when average CPU usage exceeds a threshold.",
"name": "Host CPU high",
"routing_tags": [
"sre-oncall"
],
"tags": [
"production",
"infra"
]
},
"no_data": {
"strategy": "keep_last"
},
"query": {
"base": "FROM metrics-* | STATS avg_cpu = AVG(host.cpu.usage) BY host.name",
"breach": {
"segment": "WHERE avg_cpu > 0.9"
}
},
"recovery": {
"strategy": "no_breach"
},
"schedule": {
"every": "1m",
"lookback": "5m"
},
"state_transition": {
"pending": {
"count": 1
},
"recovering": {
"count": 1
}
},
"time_field": "@timestamp",
"updated_at": "2026-01-15T12:00:00.000Z",
"updated_by": {
"profile_uid": "u_elastic_0"
},
"version": 1
}
{
"code": "BAD_REQUEST",
"details": {
"errors": {
"metadata": [
"Required"
]
}
},
"error": "Bad Request",
"message": "metadata: Required"
}
{
"code": "UNAUTHORIZED",
"error": "Unauthorized",
"message": "Authentication required to access this API."
}
{
"code": "FORBIDDEN",
"error": "Forbidden",
"message": "The current user does not have the required privileges for this request."
}
{
"code": "INTERNAL_SERVER_ERROR",
"error": "Internal Server Error",
"message": "An unexpected error occurred."
}
{
"code": "ALERTING_DISABLED",
"error": "Service Unavailable",
"message": "Alerting is disabled."
}