Loading

stack kb alerting post-alerting-rule-id cli command

Auth required
elastic stack kb alerting post-alerting-rule-id \
  --id <id> \
  --consumer <consumer> \
  --name <name> \
  --rule-type-id <rule-type-id> \
  --schedule <schedule> \
  [options]
		

Create a rule

Behaviour flags:

--dry-run — validate all inputs and exit without performing any action

--id string required
The identifier for the rule. If it is omitted, an ID is randomly generated.
--consumer string required
The name of the application or feature that owns the rule. For example: alerts, apm, discover, infrastructure, logs, metrics, ml, monitoring, securitySolution, siem, stackAlerts, or uptime.
--name string required
The name of the rule. While this name does not have to be unique, a distinctive name can help you identify a rule.
--rule-type-id string required
The rule type identifier.
--schedule string required
The check interval, which specifies how frequently the rule conditions are checked.
--actions string[]
--alert-delay string
Indicates that an alert occurs only when the specified number of consecutive runs met the rule conditions.
--artifacts string
--[no-]enabled
Indicates whether you want the rule to run on an interval basis after it is created.
--flapping string
--notify-when enum

Indicates how frequently rule actions are triggered. Valid values include: onActionGroupChange: Actions run when the alert status changes; onActiveAlert: Actions run when the alert becomes active and at each check interval while the rule conditions are met; onThrottleInterval: Actions run when the alert becomes active and at the interval specified in the throttle property while the rule conditions are met. You cannot specify notify_when at both the rule and action level. The recommended approach is to set it for each action individually. If you set notify_when at the rule level and then edit the rule, it will automatically be converted to action-specific values.

Values: onActionGroupChange, onActiveAlert, onThrottleInterval

--params string
The parameters for the rule.
--tags string[]
The tags for the rule.
--throttle string
Use the throttle property in the action frequency object instead. The throttle interval, which defines how frequently rule actions are triggered. You cannot specify the throttle interval at both the rule and action level. If you set the throttle interval at the rule level and then edit the rule, it will automatically be converted to action-specific values.
--input-file string
path to a JSON file to use as command input
--[no-]dry-run
validate all inputs and exit without performing any action (preview changes without applying them)
--[no-]json

output as JSON