Loading

stack es query-rules put-rule cli command

Auth required Idempotent Scope: global
elastic stack es query-rules put-rule \
  --type <type> \
  --criteria <criteria> \
  --actions <actions> \
  --ruleset-id <ruleset-id> \
  --rule-id <rule-id> \
  [options]
		

Create or update a query rule.

Behaviour flags:

--dry-run — validate all inputs and exit without performing any action

--type enum required

The type of rule.

Values: pinned, exclude

--criteria string required

The criteria that must be met for the rule to be applied. If multiple criteria are specified for a rule, all criteria must be met for the rule to be applied.

Repeatable: pass --criteria multiple times to supply more than one value

--actions string required
The actions to take when the rule is matched. The format of this action depends on the rule type.
--ruleset-id string required
The unique identifier of the query ruleset containing the rule to be created or updated.
--rule-id string required
The unique identifier of the query rule within the specified ruleset to be created or updated.
--priority number
--[no-]error-trace
When set to true Elasticsearch will include the full stack trace of errors when they occur.
--filter-path string

Comma-separated list of filters in dot notation which reduce the response returned by Elasticsearch.

Repeatable: pass --filter-path multiple times to supply more than one value

--[no-]human
When set to true will return statistics in a format suitable for humans. For example "exists_time": "1h" for humans and "exists_time_in_millis": 3600000 for computers. When disabled the human readable values will be omitted. This makes sense for responses being consumed only by machines.
--[no-]pretty
If set to true the returned JSON will be "pretty-formatted". Only use this option for debugging only.
--input-file string
path to a JSON file to use as command input
--[no-]dry-run
validate all inputs and exit without performing any action (preview changes without applying them)
--[no-]json

output as JSON