Create an alert rule
const url = 'http://localhost:3000/api/v1/alert-rules';const options = { method: 'POST', headers: {'X-API-Key': '<X-API-Key>', 'Content-Type': 'application/json'}, body: '{"name":"CPU above 80% on edge nodes","ruleType":"DEVICE_OFFLINE","scope":"GLOBAL","targetId":"2489E9AD-2EE2-8E00-8EC9-32D5F69181C0","targetLabels":{"site":"berlin","tier":"edge"},"expression":"cpu > 80 AND device.label.tier = \"edge\" for 5m","thresholdMinutes":5,"enabled":true,"notificationTargetIds":["2489E9AD-2EE2-8E00-8EC9-32D5F69181C0"]}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url http://localhost:3000/api/v1/alert-rules \ --header 'Content-Type: application/json' \ --header 'X-API-Key: <X-API-Key>' \ --data '{ "name": "CPU above 80% on edge nodes", "ruleType": "DEVICE_OFFLINE", "scope": "GLOBAL", "targetId": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0", "targetLabels": { "site": "berlin", "tier": "edge" }, "expression": "cpu > 80 AND device.label.tier = \"edge\" for 5m", "thresholdMinutes": 5, "enabled": true, "notificationTargetIds": [ "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0" ] }'The expression is validated against the alert DSL at write time — a malformed rule is rejected here rather than silently never firing.
Authorizations
Section titled “Authorizations”Request Bodyrequired
Section titled “Request Bodyrequired”object
Human-readable rule name
Example
CPU above 80% on edge nodesCondition family the rule evaluates
Example
METRIC_THRESHOLDWhich devices the rule applies to. GLOBAL covers every device in the organization; LABEL matches the selector in targetLabels; DEVICE matches the single device in targetId.
Device id. Required when scope is DEVICE, ignored otherwise.
Label selector. Required when scope is LABEL, ignored otherwise. A device matches when every key/value pair is present on its labels.
object
Example
{ "site": "berlin", "tier": "edge"}Condition expression. Required for METRIC_THRESHOLD and WORKLOAD_CRASH; ignored for DEVICE_OFFLINE, which uses thresholdMinutes. Syntax: field op value [AND field op value ...] [for <duration>], where duration is e.g. 30s, 5m, 2h. Fields: cpu, memory, disk (percentages), restarts, containersFailed, containersRunning, errors, uptime, device.status, device.name, device.label.
Example
cpu > 80 AND device.label.tier = "edge" for 5mDEVICE_OFFLINE only: minutes without a heartbeat before the rule fires. Defaults to 5 per FR-FM-021.
Whether the rule is evaluated
Notification targets to deliver this rule’s alerts to. Ids belonging to another organization are rejected.
Responses
Section titled “Responses”object
object
object
object
object
object
Example
{ "name": "CPU above 80% on edge nodes", "ruleType": "DEVICE_OFFLINE", "scope": "GLOBAL", "expression": "cpu > 80 for 5m", "notificationTargets": [ { "name": "Ops on-call email", "channel": "EMAIL" } ]}Malformed expression, or scope/target mismatch