Replace an alert rule.
Alert rules
Replace an alert rule.
The source kind and its saved-query, finding-filter, or certificate-rule binding are immutable. Replacing a rule advances its revision so replayed source events do not become new events.
PUT
Replace an alert rule.
Authorizations
Infrawatch API key. Supply the complete key directly as the header value.
Body
application/json
- Option 1
- Option 2
- Option 3
Available options:
saved_query, finding, certificate Allowed value:
"saved_query"Minimum array length:
1Minimum array length:
1Available options:
ADDED, REMOVED, CHANGED Required range:
0 <= x <= 3600Required string length:
1 - 160Available options:
low, medium, high, critical Available options:
result_count, added_count, removed_count, changed_count Available options:
gt, gte, lt, lte, eq Required range:
x >= 0Required range:
300 <= x <= 604800Available options:
medium, high, critical Immutable source binding for a finding rule after creation.
Required range:
300 <= x <= 604800Available options:
change, count_threshold Response
Alert rule replaced.
- Option 1
- Option 2
- Option 3