Spaces method and path for this operation:
Refer to Spaces for more information.
Creates a rule with the given identifier, or fully replaces it if one already exists.
[Required authorization] Route required privileges: manage_alerting-v2-rules.
Path parameters
-
The identifier for the rule. Chosen at creation and permanent — it cannot be changed afterwards. Re-using the id of a deleted resource is allowed but discouraged: execution history, change history, and alert episodes recorded under that id are retained and are attributed to the new resource. Ids appear in URLs and logs, so keep them free of sensitive data.
Minimum length is
1, maximum length is150. Format should match the following pattern:^[a-zA-Z0-9_-]+$.
Body
-
Optional objects attached to the rule, such as a runbook or a dashboard. Each item has
id,type, anddata. The shape ofdatadepends ontype. For example, arunbookusescontentand adashboardusesdashboard_id. Known types are validated against that shape. Unknown types are stored whenid,type, anddataare present.Not more than
100elements. -
Grouping configuration.
Additional properties are NOT allowed.
- kind
string Required Whether the rule creates alerts (
alert) or only stores matching events (signal). -
Rule metadata.
Additional properties are NOT allowed.
-
ES|QL query the rule evaluates.
baseis required.breachis an optional clause appended to it.Additional properties are NOT allowed.
-
Execution schedule configuration.
Additional properties are NOT allowed.
-
Specifies how many consecutive matches, or how long a condition must hold, before an alert becomes
activeorinactive. Allowed only whenkindisalert.Additional properties are NOT allowed.
-
Document field Kibana uses with
schedule.lookbackto time-filterquery.base.Minimum length is
1, maximum length is256. Default value is@timestamp.
Responses
-
Returns the replaced rule.
-
Returns the newly created rule.
-
Indicates an invalid schema or parameters.
-
Indicates the request was not authenticated.
-
Indicates the user does not have the required privileges to perform the request.
-
Indicates the rule was created or updated concurrently, or the request changes immutable fields.
-
Indicates an unexpected server-side error.
-
Indicates the alerting engine is disabled by the
alerting:v2:enabledadvanced setting.
curl \
--request PUT 'https://<KIBANA_URL>/api/alerting/v2/rules/{id}' \
--header "Authorization: $API_KEY" \
--header "Content-Type: application/json" \
--header "kbn-xsrf: true" \
--data '{
"grouping": {
"fields": [
"host.name"
]
},
"kind": "alert",
"metadata": {
"description": "Alerts when average CPU usage exceeds a threshold.",
"name": "Host CPU high",
"routing_tags": [
"sre-oncall"
],
"tags": [
"production",
"infra"
]
},
"no_data": {
"strategy": "keep_last"
},
"query": {
"base": "FROM metrics-* | STATS avg_cpu = AVG(host.cpu.usage) BY host.name",
"breach": {
"segment": "WHERE avg_cpu > 0.9"
}
},
"recovery": {
"strategy": "no_breach"
},
"schedule": {
"every": "1m",
"lookback": "5m"
},
"state_transition": {
"pending": {
"count": 1
},
"recovering": {
"count": 1
}
},
"time_field": "@timestamp"
}'
{
"grouping": {
"fields": [
"host.name"
]
},
"kind": "alert",
"metadata": {
"description": "Alerts when average CPU usage exceeds a threshold.",
"name": "Host CPU high",
"routing_tags": [
"sre-oncall"
],
"tags": [
"production",
"infra"
]
},
"no_data": {
"strategy": "keep_last"
},
"query": {
"base": "FROM metrics-* | STATS avg_cpu = AVG(host.cpu.usage) BY host.name",
"breach": {
"segment": "WHERE avg_cpu > 0.9"
}
},
"recovery": {
"strategy": "no_breach"
},
"schedule": {
"every": "1m",
"lookback": "5m"
},
"state_transition": {
"pending": {
"count": 1
},
"recovering": {
"count": 1
}
},
"time_field": "@timestamp"
}
{
"created_at": "2026-01-15T12:00:00.000Z",
"created_by": {
"profile_uid": "u_elastic_0"
},
"enabled": true,
"grouping": {
"fields": [
"host.name"
]
},
"id": "rule-1",
"kind": "alert",
"metadata": {
"description": "Alerts when average CPU usage exceeds a threshold.",
"name": "Host CPU high",
"routing_tags": [
"sre-oncall"
],
"tags": [
"production",
"infra"
]
},
"no_data": {
"strategy": "keep_last"
},
"query": {
"base": "FROM metrics-* | STATS avg_cpu = AVG(host.cpu.usage) BY host.name",
"breach": {
"segment": "WHERE avg_cpu > 0.9"
}
},
"recovery": {
"strategy": "no_breach"
},
"schedule": {
"every": "1m",
"lookback": "5m"
},
"state_transition": {
"pending": {
"count": 1
},
"recovering": {
"count": 1
}
},
"time_field": "@timestamp",
"updated_at": "2026-01-15T12:00:00.000Z",
"updated_by": {
"profile_uid": "u_elastic_0"
},
"version": 1
}
{
"created_at": "2026-01-15T12:00:00.000Z",
"created_by": {
"profile_uid": "u_elastic_0"
},
"enabled": true,
"grouping": {
"fields": [
"host.name"
]
},
"id": "rule-1",
"kind": "alert",
"metadata": {
"description": "Alerts when average CPU usage exceeds a threshold.",
"name": "Host CPU high",
"routing_tags": [
"sre-oncall"
],
"tags": [
"production",
"infra"
]
},
"no_data": {
"strategy": "keep_last"
},
"query": {
"base": "FROM metrics-* | STATS avg_cpu = AVG(host.cpu.usage) BY host.name",
"breach": {
"segment": "WHERE avg_cpu > 0.9"
}
},
"recovery": {
"strategy": "no_breach"
},
"schedule": {
"every": "1m",
"lookback": "5m"
},
"state_transition": {
"pending": {
"count": 1
},
"recovering": {
"count": 1
}
},
"time_field": "@timestamp",
"updated_at": "2026-01-15T12:00:00.000Z",
"updated_by": {
"profile_uid": "u_elastic_0"
},
"version": 1
}
{
"code": "BAD_REQUEST",
"details": {
"errors": {
"metadata": [
"Required"
]
}
},
"error": "Bad Request",
"message": "metadata: Required"
}
{
"code": "UNAUTHORIZED",
"error": "Unauthorized",
"message": "Authentication required to access this API."
}
{
"code": "FORBIDDEN",
"error": "Forbidden",
"message": "The current user does not have the required privileges for this request."
}
{
"code": "RULE_VERSION_CONFLICT",
"details": {
"rule_id": "rule-1"
},
"error": "Conflict",
"message": "Rule with id \"rule-1\" has already been updated by another user"
}
{
"code": "INTERNAL_SERVER_ERROR",
"error": "Internal Server Error",
"message": "An unexpected error occurred."
}
{
"code": "ALERTING_DISABLED",
"error": "Service Unavailable",
"message": "Alerting is disabled."
}