Skip to main content
PUT
Update an outbound rule

Authorizations

Authorization
string
header
required

An sre_ak_* API key holding the api:admin scope (or api:config_read, which every write refuses with read_only_key).

Path Parameters

id
string
required

The resource's id.

Body

application/json
cooldown_minutes
integer | null

An immediate rule waits this long, at least 1, after a delivered page before it pages about a DIFFERENT alert; a page the target refused spends nothing, so every matching alert still gets its own attempt and its own row. A timed rule does not space its pages by this at all: one scheduled evaluation pages for every alert it matches whose firing has lasted long enough, and the number is read only as the seed of the retry wait below. Either kind of rule waits this long before re-attempting a page that could not be delivered, doubling the wait with each further failure up to one day; the immediate path makes that attempt on the next delivery of the alert that arrives after the wait, and the timed path on its next pass. Neither repeats a page that was delivered for the same firing. null leaves the default of 30 minutes.

enabled
boolean

Whether this rule may fire at all. A disabled rule keeps everything it matches on and is skipped.

escalate_after_minutes
integer | null

Makes this a timed rule, at least 1, and it changes when the rule pages rather than what it pages for. A timed rule is run by a scheduled evaluation, which pages once per firing for the alerts it matches, and only once the firing has lasted this many minutes; an alert that cleared and fired again is firing since the moment it came back, however long it was open before that. match_source, match_severity and match_labels are read the same way as on an immediate rule. A page the target refuses is attempted again at growing intervals, starting at cooldown_minutes after the failure and doubling with each further failure up to one day, and one that was delivered is never repeated for that alert and rule in that firing. null leaves the rule immediate, and an immediate rule pages for the alerts it matches as they arrive: once per firing per alert, so a redelivery of an alert that is still active does not page again and an alert that cleared and fired again does.

match_labels
object | null

Only alerts whose labels carry every one of these pairs, compared as strings, so every value here must be a string. An empty object and null both match every alert.

match_severity
string | null

Only alerts of this severity, matched exactly, one of: critical, high, warning, medium, low, info. null matches every severity.

match_source
string | null

Only alerts from this source, matched exactly, one of: grafana, pagerduty, opsgenie, prometheus, alertmanager, datadog, newrelic, cloudwatch, cloudtrail, custom, slo_breach, slo_tracking, certificate_monitor, cost_monitor, synthetic_check, slack, overseer, security. null matches every source.

name
string

What this rule is called here. It is a label for the people reading the table, not anything the target sees.

outbound_config_id
string

The target this rule escalates to, by its uuid as list_outbound_configs answers it. It must belong to this organization.

step_order
integer | null

Where this rule sits in an escalation chain. Step 0 pages first; a rule with a higher step order is skipped for a firing somebody already acknowledged, and waits for a step 0 page that nobody acknowledged before it pages. Leave it at 0 for a rule that is not part of a chain.

Response

Updated.