Note : This endpoint is in preview and is subject to change.
If you have any feedback, contact Datadog support .
POST https://api.ap1.datadoghq.com/api/v2/incidents/config/rules https://api.ap2.datadoghq.com/api/v2/incidents/config/rules https://api.datadoghq.eu/api/v2/incidents/config/rules https://api.ddog-gov.com/api/v2/incidents/config/rules https://api.us2.ddog-gov.com/api/v2/incidents/config/rules https://api.uk1.datadoghq.com/api/v2/incidents/config/rules https://api.datadoghq.com/api/v2/incidents/config/rules https://api.us3.datadoghq.com/api/v2/incidents/config/rules https://api.us5.datadoghq.com/api/v2/incidents/config/rules
Overview Create an incident rule.
This endpoint requires
any
of the following permissions:
incident_settings_writeincident_notification_settings_writeOAuth apps require the incident_settings_write authorization scope to access this endpoint.
Request Body Data (required) Incident rule payload.
Expand All
Incident rule data in a create request.
Attributes for creating an incident rule.
A query-based condition for an incident rule.
The normalized query string.
condition_table_type [required ]
The condition table type. 1 = raw query.
List of field-based conditions.
Whether the rule is enabled.
execution_type [required ]
The execution type of an incident rule.
Allowed enum values: 1,2
The UUID of the incident type this rule applies to.
Whether any condition (OR logic) should match instead of all (AND logic).
The task ID for an incident rule.
Allowed enum values: jira-create-issue-job,notify-incident-handles-job,servicenow-create-incident-job,slack-create-channel-job,zoom-create-meeting-job,google-meet-create-meeting-job,workflow-automation-job,ms-teams-create-meeting-job,google-chat-create-space-job,zoom-suppress-summarization-jobShow 2 more ,ms-teams-suppress-summarization-job,google-meet-suppress-summarization-job
The JSON-encoded payload for the task.
The trigger event for an incident rule.
Allowed enum values: incident_saved_trigger,incident_created_trigger,incident_modified_trigger
Incident rule resource type.
Allowed enum values: incident_rules
{
"data" : {
"attributes" : {
"condition" : {
"normalized_query" : "severity:SEV-1" ,
"raw_query" : "severity:SEV-1"
},
"condition_table_type" : 1 ,
"conditions" : [
{
"field" : "severity" ,
"values" : [
"SEV-1" ,
"SEV-2"
]
}
],
"enabled" : true ,
"execution_type" : 1 ,
"incident_type_uuid" : "00000000-0000-0000-0000-000000000000" ,
"match_any_condition" : false ,
"task_id" : "notify-incident-handles-job" ,
"task_payload" : "{}" ,
"trigger" : "incident_created_trigger"
},
"type" : "incident_rules"
}
} Response Created
Response with a single incident rule.
Expand All
Incident rule data in a response.
Attributes of an incident rule in a response.
A query-based condition for an incident rule.
The normalized query string.
The condition table type.
List of field-based conditions.
Timestamp when the rule was created.
UUID of the user who created the rule.
Timestamp when the rule was deleted.
Whether the rule is enabled.
The execution type of the rule.
incident_settings_association_uuid
The incident settings association UUID.
Whether any condition should match.
Timestamp when the rule was last modified.
UUID of the user who last modified the rule.
The JSON-encoded task payload.
The trigger event for the rule.
Incident rule response resource type.
Allowed enum values: incidents_rules
{
"data" : {
"attributes" : {
"condition" : {
"normalized_query" : "severity:SEV-1" ,
"raw_query" : "severity:SEV-1"
},
"condition_table_type" : 1 ,
"conditions" : [
{
"field" : "severity" ,
"values" : [
"SEV-1" ,
"SEV-2"
]
}
],
"created" : "2024-01-01T00:00:00.000Z" ,
"created_by_uuid" : "00000000-0000-0000-0000-000000000001" ,
"deleted" : null ,
"enabled" : true ,
"execution_type" : 1 ,
"incident_settings_association_uuid" : null ,
"match_any_condition" : false ,
"modified" : "2024-01-01T00:00:00.000Z" ,
"modified_by_uuid" : "00000000-0000-0000-0000-000000000001" ,
"org_id" : 123456 ,
"task_id" : "notify-incident-handles-job" ,
"task_payload" : "{}" ,
"trigger" : "incident_created_trigger"
},
"id" : "00000000-0000-0000-0000-000000000000" ,
"type" : "incidents_rules"
}
} Bad Request
{
"errors" : [
"Bad Request"
]
} Unauthorized
{
"errors" : [
"Bad Request"
]
} Forbidden
{
"errors" : [
"Bad Request"
]
} Too many requests
{
"errors" : [
"Bad Request"
]
} Code Example Copy
## default
#
# Curl command curl -X POST "https://api.ap1.datadoghq.com "https://api.ap2.datadoghq.com "https://api.datadoghq.eu "https://api.ddog-gov.com "https://api.us2.ddog-gov.com "https://api.uk1.datadoghq.com "https://api.datadoghq.com "https://api.us3.datadoghq.com "https://api.us5.datadoghq.com /api/v2/incidents/config/rules " \
-H "Accept: application/json" \
-H "Content-Type: application/json" \
-H "DD-API-KEY: ${DD_API_KEY} " \
-H "DD-APPLICATION-KEY: ${DD_APP_KEY} " \
-d @- << EOF
{
"data": {
"attributes": {
"condition": {
"raw_query": "severity:SEV-1"
},
"condition_table_type": 1,
"enabled": true,
"execution_type": 1,
"task_id": "notify-incident-handles-job",
"task_payload": "{}",
"trigger": "incident_created_trigger"
},
"type": "incident_rules"
}
}
EOF