stack kb alerting-v2 put-alerting-v2-rules-id cli command

Auth required Idempotent Scope: global
elastic stack kb alerting-v2 put-alerting-v2-rules-id \
  --id <id> \
  --kind <kind> \
  --metadata <metadata> \
  --query <query> \
  --schedule <schedule> \
  [options]
		

Create or replace a rule

Behaviour flags:

--dry-run — validate all inputs and exit without performing any action

--id string required
The identifier for the rule. Chosen at creation and permanent — it cannot be changed afterwards. Re-using the id of a deleted resource is allowed but discouraged: execution history, change history, and alert episodes recorded under that id are retained and are attributed to the new resource. Ids appear in URLs and logs, so keep them free of sensitive data.
--kind string required
Whether the rule creates alerts (alert) or only stores matching events (signal).
--metadata string required
--query string required
--schedule string required
--artifacts string[]

Optional objects attached to the rule, such as a runbook or a dashboard. Each item has id, type, and data. The shape of data depends on type. For example, a runbook uses content and a dashboard uses dashboard_id. Known types are validated against that shape. Unknown types are stored when id, type, and data are present.

Repeatable: pass --artifacts multiple times to supply more than one value

--grouping string
--no-data string
--recovery string
--state-transition string
--time-field string
Document field Kibana uses with schedule.lookback to time-filter query.base.
--input-file string
path to a JSON file to use as command input
--dry-run
validate all inputs and exit without performing any action (preview changes without applying them)
--no-validate
skip input validation and send the request as-is
--output-fields string
comma-separated list of fields to include in output (dot-notation supported)
--output-template string
Mustache-like template for custom text output (e.g. "{{id}}: {{name}}")
--json

output as JSON