v1

latestOpenAPI 3.0.32026-07-232011984.8 KB
rule

create rule

post/rules

Query parameters

run-tests-firstboolean

set this field to false to exclude running tests prior to saving

set this field to false to exclude running tests prior to saving

run-tests-onlyboolean

set this field to true if you want to run tests without saving

set this field to true if you want to run tests without saving

Request body

bodystring required

The python body of the rule

createAlertboolean

Determines whether the rule should create alerts when it triggers

dedupPeriodMinutesinteger

The amount of time in minutes for grouping alerts

descriptionstring

The description of the rule

displayNamestring

The display name of the rule

enabledboolean

Determines whether or not the rule is active

idstring required

The id of the rule

inlineFiltersstring

The filter for the rule represented in YAML

logTypesstring[]

log types

managedboolean

Determines if the rule is managed by panther

outputIDsstring[]

Destination IDs that override default alert routing based on severity

referencestring

A URL or note for additional reference material

reportsobject

reports

runbookstring

How to handle the generated alert

severity'INFO' | 'LOW' | 'MEDIUM' | 'HIGH' | 'CRITICAL' required
summaryAttributesstring[]

A list of fields in the event to create top 5 summaries for

tagsstring[]

The tags for the rule

thresholdinteger

the number of events that must match before an alert is triggered

Response

OK response.

bodystring

The python body of the rule

createAlertboolean

Determines whether the rule should create alerts when it triggers

createdAtstring
createdByExternalstring

The text of the user-provided CreatedBy field when uploaded via CI/CD

dedupPeriodMinutesinteger

The amount of time in minutes for grouping alerts

descriptionstring

The description of the rule

displayNamestring

The display name of the rule

enabledboolean

Determines whether or not the rule is active

idstring

The id of the rule

inlineFiltersstring

The filter for the rule represented in YAML

lastModifiedstring
logTypesstring[]

log types

managedboolean

Determines if the rule is managed by panther

outputIDsstring[]

Destination IDs that override default alert routing based on severity

referencestring

A URL or note for additional reference material

reportsobject

reports

runbookstring

How to handle the generated alert

severity'INFO' | 'LOW' | 'MEDIUM' | 'HIGH' | 'CRITICAL'
summaryAttributesstring[]

A list of fields in the event to create top 5 summaries for

tagsstring[]

The tags for the rule

thresholdinteger

the number of events that must match before an alert is triggered