Replace the deduplication rules

Replaces the whole set. Alerts are grouped by a rule's name rather than by its expression, so refining a rule that is already live keeps everything it has matched so far in one group. A rule with no name, a name already used, or an expression that will not compile is refused. Saving a change also re-deduplicates the alerts already stored, because a rule is usually written about a queue that is already full of one fault under several wordings - the response says what moved. Alerts somebody has acknowledged, assigned or closed keep their status and their link, so this never takes work out of an operator's queue.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Query Params
boolean
Defaults to true

Re-deduplicate the alerts already stored against the new rules. On by default; turn it off to change the rules without touching the existing queue.

Body Params

The whole set of deduplication rules, in the order they are applied - first match wins, so a narrow rule belongs above a broad one. Replacing them only affects alerts raised from then on, because an alert is deduplicated once, when it is written; use the reanalysis endpoint to apply a change to alerts already stored.

patterns
array of objects
patterns
reanalysis
object

What re-deduplicating the alerts already stored did, when saving these rules changed them. Absent on a read, and on a save that changed nothing or asked not to re-deduplicate.

Responses

Language
Credentials
Bearer
JWT
URL
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json