Update an incident rule

Note: This endpoint is in preview and is subject to change. If you have any feedback, contact Datadog support.

PATCH https://api.ap1.datadoghq.com/api/v2/incidents/config/rules/{rule_id}https://api.ap2.datadoghq.com/api/v2/incidents/config/rules/{rule_id}https://api.datadoghq.eu/api/v2/incidents/config/rules/{rule_id}https://api.ddog-gov.com/api/v2/incidents/config/rules/{rule_id}https://api.us2.ddog-gov.com/api/v2/incidents/config/rules/{rule_id}https://api.uk1.datadoghq.com/api/v2/incidents/config/rules/{rule_id}https://api.datadoghq.com/api/v2/incidents/config/rules/{rule_id}https://api.us3.datadoghq.com/api/v2/incidents/config/rules/{rule_id}https://api.us5.datadoghq.com/api/v2/incidents/config/rules/{rule_id}

Overview

Update an incident rule. This endpoint requires any of the following permissions:

  • incident_settings_write
  • incident_notification_settings_write

  • OAuth apps require the incident_settings_write authorization scope to access this endpoint.

    Arguments

    Path Parameters

    Name

    Type

    Description

    rule_id [required]

    string

    The UUID of the incident rule.

    Request

    Body Data (required)

    Incident rule patch payload.

    Expand All

    Field

    Type

    Description

    data [required]

    object

    Incident rule data in a patch request.

    attributes

    object

    Attributes for patching an incident rule. All fields are optional.

    condition

    object

    A query-based condition for an incident rule.

    normalized_query

    string

    The normalized query string.

    raw_query

    string

    The raw query string.

    conditions

    [object]

    List of field-based conditions.

    field [required]

    string

    The field to match on.

    values [required]

    [string]

    The values to match.

    enabled

    boolean

    Whether the rule is enabled.

    task_payload

    string

    The JSON-encoded payload for the task.

    trigger

    enum

    The trigger event for an incident rule. Allowed enum values: incident_saved_trigger,incident_created_trigger,incident_modified_trigger

    id [required]

    uuid

    The rule identifier.

    type [required]

    enum

    Incident rule resource type. Allowed enum values: incident_rules

    {
      "data": {
        "attributes": {
          "condition": {
            "normalized_query": "severity:SEV-1",
            "raw_query": "severity:SEV-1"
          },
          "conditions": [
            {
              "field": "severity",
              "values": [
                "SEV-1",
                "SEV-2"
              ]
            }
          ],
          "enabled": true,
          "task_payload": "{}",
          "trigger": "incident_created_trigger"
        },
        "id": "00000000-0000-0000-0000-000000000000",
        "type": "incident_rules"
      }
    }

    Response

    OK

    Response with a single incident rule.

    Expand All

    Field

    Type

    Description

    data [required]

    object

    Incident rule data in a response.

    attributes [required]

    object

    Attributes of an incident rule in a response.

    condition

    object

    A query-based condition for an incident rule.

    normalized_query

    string

    The normalized query string.

    raw_query

    string

    The raw query string.

    condition_table_type

    int64

    The condition table type.

    conditions

    [object]

    List of field-based conditions.

    field [required]

    string

    The field to match on.

    values [required]

    [string]

    The values to match.

    created

    date-time

    Timestamp when the rule was created.

    created_by_uuid

    uuid

    UUID of the user who created the rule.

    deleted

    date-time

    Timestamp when the rule was deleted.

    enabled

    boolean

    Whether the rule is enabled.

    execution_type

    int64

    The execution type of the rule.

    incident_settings_association_uuid

    uuid

    The incident settings association UUID.

    match_any_condition

    boolean

    Whether any condition should match.

    modified

    date-time

    Timestamp when the rule was last modified.

    modified_by_uuid

    uuid

    UUID of the user who last modified the rule.

    org_id

    int64

    The organization ID.

    task_id

    string

    The task ID.

    task_payload

    string

    The JSON-encoded task payload.

    trigger

    string

    The trigger event for the rule.

    id [required]

    uuid

    The rule identifier.

    type [required]

    enum

    Incident rule response resource type. Allowed enum values: incidents_rules

    {
      "data": {
        "attributes": {
          "condition": {
            "normalized_query": "severity:SEV-1",
            "raw_query": "severity:SEV-1"
          },
          "condition_table_type": 1,
          "conditions": [
            {
              "field": "severity",
              "values": [
                "SEV-1",
                "SEV-2"
              ]
            }
          ],
          "created": "2024-01-01T00:00:00.000Z",
          "created_by_uuid": "00000000-0000-0000-0000-000000000001",
          "deleted": null,
          "enabled": true,
          "execution_type": 1,
          "incident_settings_association_uuid": null,
          "match_any_condition": false,
          "modified": "2024-01-01T00:00:00.000Z",
          "modified_by_uuid": "00000000-0000-0000-0000-000000000001",
          "org_id": 123456,
          "task_id": "notify-incident-handles-job",
          "task_payload": "{}",
          "trigger": "incident_created_trigger"
        },
        "id": "00000000-0000-0000-0000-000000000000",
        "type": "incidents_rules"
      }
    }

    Bad Request

    API error response.

    Expand All

    Field

    Type

    Description

    errors [required]

    [string]

    A list of errors.

    {
      "errors": [
        "Bad Request"
      ]
    }

    Unauthorized

    API error response.

    Expand All

    Field

    Type

    Description

    errors [required]

    [string]

    A list of errors.

    {
      "errors": [
        "Bad Request"
      ]
    }

    Forbidden

    API error response.

    Expand All

    Field

    Type

    Description

    errors [required]

    [string]

    A list of errors.

    {
      "errors": [
        "Bad Request"
      ]
    }

    Not Found

    API error response.

    Expand All

    Field

    Type

    Description

    errors [required]

    [string]

    A list of errors.

    {
      "errors": [
        "Bad Request"
      ]
    }

    Too many requests

    API error response.

    Expand All

    Field

    Type

    Description

    errors [required]

    [string]

    A list of errors.

    {
      "errors": [
        "Bad Request"
      ]
    }

    Code Example

                      ## default
    # 
    
    # Path parameters
    export rule_id="CHANGE_ME"
    # Curl command
    curl -X PATCH "https://api.ap1.datadoghq.com"https://api.ap2.datadoghq.com"https://api.datadoghq.eu"https://api.ddog-gov.com"https://api.us2.ddog-gov.com"https://api.uk1.datadoghq.com"https://api.datadoghq.com"https://api.us3.datadoghq.com"https://api.us5.datadoghq.com/api/v2/incidents/config/rules/${rule_id}" \ -H "Accept: application/json" \ -H "Content-Type: application/json" \ -H "DD-API-KEY: ${DD_API_KEY}" \ -H "DD-APPLICATION-KEY: ${DD_APP_KEY}" \ -d @- << EOF { "data": { "attributes": { "enabled": false }, "id": "00000000-0000-0000-0000-000000000001", "type": "incident_rules" } } EOF