﻿---
title: stack kb alerting-v2 put-alerting-v2-rules-id cli command
description: Create or replace a rule Behaviour flags: --dry-run — validate all inputs and exit without performing any action 
url: https://www.elastic.co/elastic/docs-builder/docs/4384/reference/elastic-cli/cli/stack/kb/alerting-v2/put-alerting-v2-rules-id
applies_to:
  - Elastic Cloud Serverless: Preview
  - Elastic Stack: Preview
---

# stack kb alerting-v2 put-alerting-v2-rules-id cli command
<cli-modifiers>
</cli-modifiers>

```bash
elastic stack kb alerting-v2 put-alerting-v2-rules-id \
  --id <id> \
  --kind <kind> \
  --metadata <metadata> \
  --query <query> \
  --schedule <schedule> \
  [options]
```

Create or replace a rule
**Behaviour flags:**
`--dry-run` — validate all inputs and exit without performing any action

## Options

<definitions>
  <definition term="--id string required">
    The identifier for the rule. Chosen at creation and permanent — it cannot be changed afterwards. Re-using the id of a deleted resource is allowed but discouraged: execution history, change history, and alert episodes recorded under that id are retained and are attributed to the new resource. Ids appear in URLs and logs, so keep them free of sensitive data.
  </definition>
  <definition term="--kind string required">
    Whether the rule creates alerts (`alert`) or only stores matching events (`signal`).
  </definition>
  <definition term="--metadata string required">
  </definition>
  <definition term="--query string required">
  </definition>
  <definition term="--schedule string required">
  </definition>
  <definition term="--artifacts string[]">
    Optional objects attached to the rule, such as a runbook or a dashboard. Each item has `id`, `type`, and `data`. The shape of `data` depends on `type`. For example, a `runbook` uses `content` and a `dashboard` uses `dashboard_id`. Known types are validated against that shape. Unknown types are stored when `id`, `type`, and `data` are present.
    **Repeatable:** pass `--artifacts` multiple times to supply more than one value
  </definition>
  <definition term="--grouping string">
  </definition>
  <definition term="--no-data string">
  </definition>
  <definition term="--recovery string">
  </definition>
  <definition term="--state-transition string">
  </definition>
  <definition term="--time-field string">
    Document field Kibana uses with `schedule.lookback` to time-filter `query.base`.
  </definition>
  <definition term="--input-file string">
    path to a JSON file to use as command input
  </definition>
  <definition term="--dry-run">
    validate all inputs and exit without performing any action (preview changes without applying them)
  </definition>
  <definition term="--no-validate">
    skip input validation and send the request as-is
  </definition>
</definitions>


## Global Options

<definitions>
  <definition term="--output-fields string">
    comma-separated list of fields to include in output (dot-notation supported)
  </definition>
  <definition term="--output-template string">
    Mustache-like template for custom text output (e.g. "{{id}}: {{name}}")
  </definition>
  <definition term="--json">
    output as JSON
  </definition>
</definitions>