At least 1 but not more than 100 elements. Minimum length of each is 1, maximum length of each is 150. Format of each should match the following pattern: ^[a-zA-Z0-9_-]+$.
The requested rules, in the same order as the requested ids.
Hide items attributesShow items attributesobject
artifacts
array[object]
Optional objects attached to the rule, such as a runbook or a dashboard. Each item has id, type, and data. The shape of data depends on type. For example, a runbook uses content and a dashboard uses dashboard_id. Known types are validated against that shape. Unknown types are stored when id, type, and data are present.
Format should match the following pattern: ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$.
Creates an alert for each matching group and tracks it until it recovers. Use this when you want to detect a problem and notify or automate a response.
Value is alert.
Stores each match as a rule event you can query. Alerts are not created and notifications are not sent.
Identifies the rule builder that authored this rule (e.g. "threshold"). Absent for rules authored directly in ES|QL.
Maximum length is 64.
description
string
Human-readable description of the rule.
Maximum length is 1024.
name
stringRequired
Rule name (must be unique within the space).
Minimum length is 1, maximum length is 256.
routing_tags
array[string]
Routing tags that link alerts from this rule to action policies. An action policy applies when its matcher.tags contains at least one of these tags. Only allowed when kind is "alert".
At least 1 but not more than 20 elements. Minimum length of each is 1, maximum length of each is 128.
tags
array[string]
Tags for categorization, e.g. ["production", "infra"].
At least 1 but not more than 20 elements. Minimum length of each is 1, maximum length of each is 128.
no_data
object
What the rule does when a group has no data. Required when kind is alert. Not allowed when kind is signal. Any strategy other than ignore requires either query.breach or no_data.query, so that a group with no data can be told apart from one that stopped breaching.
Does not check whether a group still has data. Missing groups do not produce no_data events.
Hide attributeShow attribute
strategy
stringRequiredDiscriminator
Value is ignore.
Holds the alert's current status when the rule finds no data.
Hide attributesShow attributes
query
string
Optional ES|QL query that checks whether a group has data. If omitted, query.base is used, which then has to be a presence query in its own right — so query.breach is required.
Minimum length is 1, maximum length is 10000.
strategy
stringRequiredDiscriminator
Value is keep_last.
Closes the alert the first time the rule finds no data for a group.
Hide attributesShow attributes
query
string
Optional ES|QL query that checks whether a group has data. If omitted, query.base is used, which then has to be a presence query in its own right — so query.breach is required.
Minimum length is 1, maximum length is 10000.
strategy
stringRequiredDiscriminator
Value is resolve.
Marks an existing alert active when the rule finds no data. It never opens an alert for a group that has not breached. Not accepted when creating or updating rules.
Hide attributesShow attributes
query
string
Optional ES|QL query that checks whether a group has data. If omitted, query.base is used, which then has to be a presence query in its own right — so query.breach is required.
Minimum length is 1, maximum length is 10000.
strategy
stringRequiredDiscriminator
Value is alert.
query
objectRequired
ES|QL query the rule evaluates. base is required. breach is an optional clause appended to it.
Additional properties are NOT allowed.
Hide query attributesShow query attributesobject
base
stringRequired
ES|QL query that specifies the data to evaluate. Must include a FROM clause. Kibana applies the time filter from schedule.lookback using time_field.
Minimum length is 1, maximum length is 10000.
breach
object
Optional ES|QL clause appended to query.base. If omitted, every row from query.base is a match, and a no_data strategy other than ignore then requires no_data.query.
Additional properties are NOT allowed.
Hide breach attributeShow breach attributeobject
segment
stringRequired
ES|QL clause appended to query.base, for example WHERE avg_cpu > 0.85. Don't include a FROM clause.
Minimum length is 1, maximum length is 10000.
recovery
object
When an alert recovers. Required when kind is alert. Not allowed when kind is signal.
Lookback window for the query, e.g. 5m, 1h. Can also be expressed in ES|QL.
Maximum length is 32.
state_transition
object
Specifies how many consecutive matches, or how long a condition must hold, before an alert becomes active or inactive. Allowed only when kind is alert.
Consecutive matches the alert spends in pending before it becomes active on the next match. For example, 2 opens it on the third consecutive match. Set to 0 to open it on the first match.
Minimum value is 0, maximum value is 1000.
operator
string
When both count and timeframe are set, and requires both and or requires either. Allowed only when both fields are present.
Values are and or or.
timeframe
string
Duration the condition must hold, for example 5m. Combine with count using operator.
Maximum length is 32.
recovering
object
Delay before a recovered match closes the alert. Has no effect when recovery.strategy is manual.
Consecutive recoveries the alert spends in recovering before it becomes inactive on the next recovery. For example, 2 closes it on the third consecutive recovery. Set to 0 to close it on the first recovery.
Minimum value is 0, maximum value is 1000.
operator
string
When both count and timeframe are set, and requires both and or requires either. Allowed only when both fields are present.
Values are and or or.
timeframe
string
Duration the condition must hold, for example 5m. Combine with count using operator.
Maximum length is 32.
time_field
string
Document field Kibana uses with schedule.lookback to time-filter query.base.
Minimum length is 1, maximum length is 256. Default value is @timestamp.
updated_at
string(date-time)Required
ISO timestamp when the rule was last updated.
Format should match the following pattern: ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$.
User profile ID of the actor, or null when it cannot be resolved.
version
integerRequired
Monotonically increasing integer number representing a rule configuration version, incremented on every change. Used on generated rule events as rule.version.
Minimum value is 1, maximum value is 9007199254740991.
Stable error code you can branch on, for example INVALID_SCHEDULE or RULE_ALREADY_EXISTS.
details
object
Optional extra information about the error, for example field validation issues or the rule_id when that ID already exists.
Additional properties are allowed.
error
stringRequired
A short human-readable summary of the error category (e.g., "Not Found", "Bad Request"). Subject to change without notice. Do not parse or rely on its content.
message
stringRequired
A readable explanation of the error. The wording can change without notice. Do not parse this field.
Stable error code you can branch on, for example INVALID_SCHEDULE or RULE_ALREADY_EXISTS.
details
object
Optional extra information about the error, for example field validation issues or the rule_id when that ID already exists.
Additional properties are allowed.
error
stringRequired
A short human-readable summary of the error category (e.g., "Not Found", "Bad Request"). Subject to change without notice. Do not parse or rely on its content.
message
stringRequired
A readable explanation of the error. The wording can change without notice. Do not parse this field.
403
application/json
Indicates the user does not have the required privileges to perform the request.
Stable error code you can branch on, for example INVALID_SCHEDULE or RULE_ALREADY_EXISTS.
details
object
Optional extra information about the error, for example field validation issues or the rule_id when that ID already exists.
Additional properties are allowed.
error
stringRequired
A short human-readable summary of the error category (e.g., "Not Found", "Bad Request"). Subject to change without notice. Do not parse or rely on its content.
message
stringRequired
A readable explanation of the error. The wording can change without notice. Do not parse this field.
Stable error code you can branch on, for example INVALID_SCHEDULE or RULE_ALREADY_EXISTS.
details
object
Optional extra information about the error, for example field validation issues or the rule_id when that ID already exists.
Additional properties are allowed.
error
stringRequired
A short human-readable summary of the error category (e.g., "Not Found", "Bad Request"). Subject to change without notice. Do not parse or rely on its content.
message
stringRequired
A readable explanation of the error. The wording can change without notice. Do not parse this field.
Stable error code you can branch on, for example INVALID_SCHEDULE or RULE_ALREADY_EXISTS.
details
object
Optional extra information about the error, for example field validation issues or the rule_id when that ID already exists.
Additional properties are allowed.
error
stringRequired
A short human-readable summary of the error category (e.g., "Not Found", "Bad Request"). Subject to change without notice. Do not parse or rely on its content.
message
stringRequired
A readable explanation of the error. The wording can change without notice. Do not parse this field.
503
application/json
Indicates the alerting engine is disabled by the alerting:v2:enabled advanced setting.
Stable error code you can branch on, for example INVALID_SCHEDULE or RULE_ALREADY_EXISTS.
details
object
Optional extra information about the error, for example field validation issues or the rule_id when that ID already exists.
Additional properties are allowed.
error
stringRequired
A short human-readable summary of the error category (e.g., "Not Found", "Bad Request"). Subject to change without notice. Do not parse or rely on its content.
message
stringRequired
A readable explanation of the error. The wording can change without notice. Do not parse this field.