stack kb alerting-v2 put-alerting-v2-rules-id cli command
Auth required
Idempotent
Scope: global
elastic stack kb alerting-v2 put-alerting-v2-rules-id \
--id <id> \
--kind <kind> \
--metadata <metadata> \
--query <query> \
--schedule <schedule> \
[options]
Create or replace a rule
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--idstringrequired- The identifier for the rule. Chosen at creation and permanent — it cannot be changed afterwards. Re-using the id of a deleted resource is allowed but discouraged: execution history, change history, and alert episodes recorded under that id are retained and are attributed to the new resource. Ids appear in URLs and logs, so keep them free of sensitive data.
--kindstringrequired- Whether the rule creates alerts (
alert) or only stores matching events (signal). --metadatastringrequired--querystringrequired--schedulestringrequired--artifactsstring[]-
Optional objects attached to the rule, such as a runbook or a dashboard. Each item has
id,type, anddata. The shape ofdatadepends ontype. For example, arunbookusescontentand adashboardusesdashboard_id. Known types are validated against that shape. Unknown types are stored whenid,type, anddataare present.Repeatable: pass
--artifactsmultiple times to supply more than one value --groupingstring--no-datastring--recoverystring--state-transitionstring--time-fieldstring- Document field Kibana uses with
schedule.lookbackto time-filterquery.base. --input-filestring- path to a JSON file to use as command input
--dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--no-validate- skip input validation and send the request as-is
--output-fieldsstring- comma-separated list of fields to include in output (dot-notation supported)
--output-templatestring- Mustache-like template for custom text output (e.g. "{{id}}: {{name}}")
--json-
output as JSON