stack kb alerting-v2 post-alerting-v2-rules cli command

Auth required
elastic stack kb alerting-v2 post-alerting-v2-rules \
  --kind <kind> \
  --metadata <metadata> \
  --query <query> \
  --schedule <schedule> \
  [options]
		

Create a rule

Behaviour flags:

--dry-run — validate all inputs and exit without performing any action

--kind string required
Whether the rule creates alerts (alert) or only stores matching events (signal).
--metadata string required
--query string required
--schedule string required
--artifacts string[]

Optional objects attached to the rule, such as a runbook or a dashboard. Each item has id, type, and data. The shape of data depends on type. For example, a runbook uses content and a dashboard uses dashboard_id. Known types are validated against that shape. Unknown types are stored when id, type, and data are present.

Repeatable: pass --artifacts multiple times to supply more than one value

--grouping string
--no-data string
--recovery string
--state-transition string
--time-field string
Document field Kibana uses with schedule.lookback to time-filter query.base.
--input-file string
path to a JSON file to use as command input
--dry-run
validate all inputs and exit without performing any action (preview changes without applying them)
--no-validate
skip input validation and send the request as-is
--output-fields string
comma-separated list of fields to include in output (dot-notation supported)
--output-template string
Mustache-like template for custom text output (e.g. "{{id}}: {{name}}")
--json

output as JSON