stack kb alerting-v2 post-alerting-v2-rules cli command
Auth required
elastic stack kb alerting-v2 post-alerting-v2-rules \
--kind <kind> \
--metadata <metadata> \
--query <query> \
--schedule <schedule> \
[options]
Create a rule
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--kindstringrequired- Whether the rule creates alerts (
alert) or only stores matching events (signal). --metadatastringrequired--querystringrequired--schedulestringrequired--artifactsstring[]-
Optional objects attached to the rule, such as a runbook or a dashboard. Each item has
id,type, anddata. The shape ofdatadepends ontype. For example, arunbookusescontentand adashboardusesdashboard_id. Known types are validated against that shape. Unknown types are stored whenid,type, anddataare present.Repeatable: pass
--artifactsmultiple times to supply more than one value --groupingstring--no-datastring--recoverystring--state-transitionstring--time-fieldstring- Document field Kibana uses with
schedule.lookbackto time-filterquery.base. --input-filestring- path to a JSON file to use as command input
--dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--no-validate- skip input validation and send the request as-is
--output-fieldsstring- comma-separated list of fields to include in output (dot-notation supported)
--output-templatestring- Mustache-like template for custom text output (e.g. "{{id}}: {{name}}")
--json-
output as JSON