Skip to content
qibdo qibdo
v1
API version
  • v1
Theme
Book a demo

Update Alert Rule

PATCH
/observability/v1/workspaces/{workspace}/engines/{engine}/alert-rules/{id}
curl --request PATCH \
--url https://example.com/observability/v1/workspaces/example/engines/example/alert-rules/example \
--header 'Content-Type: application/json' \
--data '{ "location_id": "example", "name": "example", "kind": "ALERT_KIND_UNSPECIFIED", "signal": "ALERT_SIGNAL_UNSPECIFIED", "qibdo": { "expression": "example", "for_duration": "example", "labels": { "additionalProperty": "example" }, "annotations": { "additionalProperty": "example" }, "route": { "group_by": [ "example" ], "matchers": [ { "label": "example", "value": "example" } ], "child_routes": [], "receivers": [ { "webhook": { "url": "example" }, "email": { "addresses": [ "example" ] }, "slack": { "channel": "example", "credential_ref": "example" } } ] } } }'

Updates an alert rule’s expression, timing, labels, and route. The workspace, location, name, kind, signal, and provider are immutable.

workspace
required
string

The workspace the alert rule belongs to.

engine
required
string

The provider: qibdo, aws, gcp, or azure, or ’-’ to target across all providers.

id
required
string

The unique identifier of the alert rule to update.

update_mask
string format: field-mask

The set of fields to update. If omitted, all mutable fields are overwritten (AIP-134).

Media type application/json

An alert rule evaluates a PromQL/LogQL expression over a signal (metric or log) and, for ALERT-kind rules, routes fired alerts through a notification tree to webhook, email, or app-message receivers. A RECORDING-kind rule instead precomputes a derived series and needs no route. The provider that evaluates the rule is reported by the read-only engine field.

object
id

The unique identifier of the alert rule.

stringOutput only
workspace_id

The workspace this rule belongs to. Derived from the {workspace} path segment on create; reported read-only thereafter.

stringOutput only
location_id
required

Weak reference to a topology Location: where the telemetry resides. Immutable after create.

string
name
required

The rule’s handle: a DNS-label (lowercase alphanumerics and hyphens, up to 63 characters), unique within the workspace. Set on create, immutable thereafter.

string
kind
required

Whether the rule raises notifications (ALERT) or precomputes a series (RECORDING). Immutable after create.

string format: enum
Allowed values: ALERT_KIND_UNSPECIFIED ALERT_KIND_ALERT ALERT_KIND_RECORDING
signal
required

The signal the rule’s expression evaluates over (metric or log). Immutable after create.

string format: enum
Allowed values: ALERT_SIGNAL_UNSPECIFIED ALERT_SIGNAL_METRIC ALERT_SIGNAL_LOG
engine

The provider that evaluates this rule.

string format: enum Output only
Allowed values: ENGINE_UNSPECIFIED ENGINE_QIBDO ENGINE_AWS ENGINE_GCP ENGINE_AZURE
create_time

Timestamp when the rule was created.

string format: date-time Output only
update_time

Timestamp when the rule was last updated.

string format: date-time Output only
qibdo

Rule spec for a Qibdo-managed alert rule.

object
expression
required

The PromQL/LogQL expression the rule evaluates (required).

string
for_duration

Pending duration the condition must hold before firing. Unset (or zero) means fire immediately.

string
/^-?(?:0|[1-9][0-9]{0,11})(?:\.[0-9]{1,9})?s$/
labels

Labels stamped onto fired alerts.

object
key
additional properties
string
annotations

Annotations attached to fired alerts.

object
key
additional properties
string
route

The notification routing tree. Optional; a recording rule omits it.

object
group_by

Label keys to group fired alerts by before notifying.

Array<string>
matchers

Label-equality predicates selecting which fired alerts this route applies to.

Array<object>

A label-equality predicate selecting which fired alerts a route applies to.

object
label
required

The alert label to match on.

string
value
required

The value the label must equal.

string
child_routes

More specific routes evaluated within this one.

Array<object>

A node in an alert rule’s notification routing tree: group fired alerts, select them by matchers, deliver to receivers, and recurse into more specific child routes.

object
group_by

Label keys to group fired alerts by before notifying.

Array<string>
matchers

Label-equality predicates selecting which fired alerts this route applies to.

Array<object>

A label-equality predicate selecting which fired alerts a route applies to.

object
label
required

The alert label to match on.

string
value
required

The value the label must equal.

string
child_routes
Array<object> recursive
receivers

The receivers fired alerts matching this route are delivered to.

Array<object>

A delivery target for a fired alert: exactly one channel arm is set.

object
webhook

Generic HTTP callback delivery.

object
url
required

The callback URL fired alerts are POSTed to.

string
email

Email delivery.

object
addresses

The recipient email addresses.

Array<string>
slack

Slack delivery.

object
channel
required

The Slack channel fired alerts are delivered to.

string
credential_ref
required

A weak reference to the Slack credential (never an inline secret).

string
receivers

The receivers fired alerts matching this route are delivered to.

Array<object>

A delivery target for a fired alert: exactly one channel arm is set.

object
webhook

Generic HTTP callback delivery.

object
url
required

The callback URL fired alerts are POSTed to.

string
email

Email delivery.

object
addresses

The recipient email addresses.

Array<string>
slack

Slack delivery.

object
channel
required

The Slack channel fired alerts are delivered to.

string
credential_ref
required

A weak reference to the Slack credential (never an inline secret).

string

OK

Media type application/json

Observability Operation

An acknowledgment of a config-plane mutation request (retention, sink, or ingestion), carrying tracking metadata, errors, and warnings. Engine-neutral: operations carry no engine axis. Follows GCP’s Operations pattern (AIP-151).

object
id

Operation ID

Unique identifier for this operation.

stringOutput only
resource_id

Resource ID

The ID of the resource affected by this operation. May be empty for async operations where the resource does not yet exist.

stringOutput only
resource_type

Resource Type

The type of resource (e.g., “com.qibdo.cloud.observability:alertrule”).

stringOutput only
operation_type

Operation Type

The kind of mutation that was requested.

string format: enum Output only
Allowed values: OBSERVABILITY_OPERATION_TYPE_UNSPECIFIED OBSERVABILITY_OPERATION_TYPE_CREATE OBSERVABILITY_OPERATION_TYPE_UPDATE OBSERVABILITY_OPERATION_TYPE_DELETE
status

Status

Current lifecycle state of the operation.

string format: enum Output only
Allowed values: OBSERVABILITY_OPERATION_STATUS_UNSPECIFIED OBSERVABILITY_OPERATION_STATUS_PENDING OBSERVABILITY_OPERATION_STATUS_RUNNING OBSERVABILITY_OPERATION_STATUS_DONE OBSERVABILITY_OPERATION_STATUS_ERROR
insert_time

Insert Time

When the operation was first created.

string format: date-time Output only
start_time

Start Time

When the operation started executing.

string format: date-time Output only
end_time

End Time

When the operation completed (either successfully or with errors).

string format: date-time Output only
errors

Errors

Business rule errors encountered during the operation.

Array<object>Output only

Operation Error

A structured error returned inside an operation when a business rule fails.

object
code

Error Code

Numeric identifier following the S_SSS_EEE convention.

integer format: uint32 Output only
description

Description

Human-readable explanation of the error.

stringOutput only
reason

Reason

Machine-readable error identifier in UPPER_SNAKE form — the same dispatch key google.rpc.ErrorInfo.reason carries on the synchronous error plane.

stringOutput only
warnings

Warnings

Non-fatal notices about the operation.

Array<object>Output only

Operation Warning

A non-fatal notice attached to an operation.

object
code

Warning Code

Numeric identifier following the S_SSS_EEE convention.

integer format: uint32 Output only
description

Description

Human-readable explanation of the warning.

stringOutput only
progress

Progress

Percentage of completion (0-100).

integer format: int32 Output only
scope_type

Scope Type

The category of scope the operation ran in or was triggered from. OBSERVABILITY_SCOPE_TYPE_UNSPECIFIED when the operation is not scoped.

string format: enum Output only
Allowed values: OBSERVABILITY_SCOPE_TYPE_UNSPECIFIED OBSERVABILITY_SCOPE_TYPE_PLATFORM OBSERVABILITY_SCOPE_TYPE_ORGANISATION OBSERVABILITY_SCOPE_TYPE_WORKSPACE OBSERVABILITY_SCOPE_TYPE_GROUP
scope_id

Scope ID

The resource this operation was scoped to — for example, when scope_type is OBSERVABILITY_SCOPE_TYPE_WORKSPACE this is the workspace id. Empty for OBSERVABILITY_SCOPE_TYPE_PLATFORM, which has no scoped resource, and when unscoped.

stringOutput only
principal_id

Principal ID

Who performed or triggered the operation, whether a person or a machine account. Always populated: platform-driven work records the reserved system principal, so every audit record names an actor.

stringOutput only
trace_id

Trace ID

W3C trace id, for correlating this operation with the traces and log lines of the request that caused it. Empty when the operation ran with no trace context — a scheduled or event-driven action rather than a request.

stringOutput only
Example
{
"operation_type": "OBSERVABILITY_OPERATION_TYPE_UNSPECIFIED",
"status": "OBSERVABILITY_OPERATION_STATUS_UNSPECIFIED",
"scope_type": "OBSERVABILITY_SCOPE_TYPE_UNSPECIFIED"
}

Default error response

Media type application/json

The Status type defines a logical error model that is suitable for different programming environments, including REST APIs and RPC APIs. It is used by gRPC. Each Status message contains three pieces of data: error code, error message, and error details. You can find out more about this error model and how to work with it in the API Design Guide.

object
code

The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code].

integer format: int32
message

A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client.

string
details

A list of messages that carry the error details. There is a common set of message types for APIs to use.

Array<object>

Contains an arbitrary serialized message along with a @type that describes the type of the serialized message.

object
@type

The type of the serialized message.

string
key
additional properties
any
Example generated
{
"code": 1,
"message": "example",
"details": [
{
"@type": "example"
}
]
}