List incident rules

Note: This endpoint is in preview and is subject to change. If you have any feedback, contact Datadog support.

GET https://api.ap1.datadoghq.com/api/v2/incidents/config/ruleshttps://api.ap2.datadoghq.com/api/v2/incidents/config/ruleshttps://api.datadoghq.eu/api/v2/incidents/config/ruleshttps://api.ddog-gov.com/api/v2/incidents/config/ruleshttps://api.us2.ddog-gov.com/api/v2/incidents/config/ruleshttps://api.uk1.datadoghq.com/api/v2/incidents/config/ruleshttps://api.datadoghq.com/api/v2/incidents/config/ruleshttps://api.us3.datadoghq.com/api/v2/incidents/config/ruleshttps://api.us5.datadoghq.com/api/v2/incidents/config/rules

Overview

List all incident rules. This endpoint requires any of the following permissions:

  • incident_settings_read
  • incident_notification_settings_read

  • OAuth apps require the incident_settings_read authorization scope to access this endpoint.

    Arguments

    Query Strings

    Name

    Type

    Description

    filter[task_id]

    string

    Filter rules by task ID.

    filter[trigger]

    string

    Filter rules by trigger.

    incidentTypeUUID

    string

    Filter rules by incident type UUID.

    Response

    OK

    Response with a list of incident rules.

    Expand All

    Field

    Type

    Description

    data [required]

    [object]

    List of incident rules.

    attributes [required]

    object

    Attributes of an incident rule in a response.

    condition

    object

    A query-based condition for an incident rule.

    normalized_query

    string

    The normalized query string.

    raw_query

    string

    The raw query string.

    condition_table_type

    int64

    The condition table type.

    conditions

    [object]

    List of field-based conditions.

    field [required]

    string

    The field to match on.

    values [required]

    [string]

    The values to match.

    created

    date-time

    Timestamp when the rule was created.

    created_by_uuid

    uuid

    UUID of the user who created the rule.

    deleted

    date-time

    Timestamp when the rule was deleted.

    enabled

    boolean

    Whether the rule is enabled.

    execution_type

    int64

    The execution type of the rule.

    incident_settings_association_uuid

    uuid

    The incident settings association UUID.

    match_any_condition

    boolean

    Whether any condition should match.

    modified

    date-time

    Timestamp when the rule was last modified.

    modified_by_uuid

    uuid

    UUID of the user who last modified the rule.

    org_id

    int64

    The organization ID.

    task_id

    string

    The task ID.

    task_payload

    string

    The JSON-encoded task payload.

    trigger

    string

    The trigger event for the rule.

    id [required]

    uuid

    The rule identifier.

    type [required]

    enum

    Incident rule response resource type. Allowed enum values: incidents_rules

    {
      "data": [
        {
          "attributes": {
            "condition": {
              "normalized_query": "severity:SEV-1",
              "raw_query": "severity:SEV-1"
            },
            "condition_table_type": 1,
            "conditions": [
              {
                "field": "severity",
                "values": [
                  "SEV-1",
                  "SEV-2"
                ]
              }
            ],
            "created": "2024-01-01T00:00:00.000Z",
            "created_by_uuid": "00000000-0000-0000-0000-000000000001",
            "deleted": null,
            "enabled": true,
            "execution_type": 1,
            "incident_settings_association_uuid": null,
            "match_any_condition": false,
            "modified": "2024-01-01T00:00:00.000Z",
            "modified_by_uuid": "00000000-0000-0000-0000-000000000001",
            "org_id": 123456,
            "task_id": "notify-incident-handles-job",
            "task_payload": "{}",
            "trigger": "incident_created_trigger"
          },
          "id": "00000000-0000-0000-0000-000000000000",
          "type": "incidents_rules"
        }
      ]
    }

    Bad Request

    API error response.

    Expand All

    Field

    Type

    Description

    errors [required]

    [string]

    A list of errors.

    {
      "errors": [
        "Bad Request"
      ]
    }

    Unauthorized

    API error response.

    Expand All

    Field

    Type

    Description

    errors [required]

    [string]

    A list of errors.

    {
      "errors": [
        "Bad Request"
      ]
    }

    Forbidden

    API error response.

    Expand All

    Field

    Type

    Description

    errors [required]

    [string]

    A list of errors.

    {
      "errors": [
        "Bad Request"
      ]
    }

    Too many requests

    API error response.

    Expand All

    Field

    Type

    Description

    errors [required]

    [string]

    A list of errors.

    {
      "errors": [
        "Bad Request"
      ]
    }

    Code Example

                      # Curl command
    curl -X GET "https://api.ap1.datadoghq.com"https://api.ap2.datadoghq.com"https://api.datadoghq.eu"https://api.ddog-gov.com"https://api.us2.ddog-gov.com"https://api.uk1.datadoghq.com"https://api.datadoghq.com"https://api.us3.datadoghq.com"https://api.us5.datadoghq.com/api/v2/incidents/config/rules" \ -H "Accept: application/json" \ -H "DD-API-KEY: ${DD_API_KEY}" \ -H "DD-APPLICATION-KEY: ${DD_APP_KEY}"