v1

latestOpenAPI 3.0.32026-07-232011984.8 KB
scheduled rule

create scheduled rule

post/scheduled-rules

Query parameters

run-tests-firstboolean

set this field to false to exclude running tests prior to saving

set this field to false to exclude running tests prior to saving

run-tests-onlyboolean

set this field to true if you want to run tests without saving

set this field to true if you want to run tests without saving

Request body

bodystring required

The python body of the scheduled rule

createAlertboolean

Determines whether the scheduled rule should create alerts when it triggers

dedupPeriodMinutesinteger

The amount of time in minutes for grouping alerts

descriptionstring

The description of the scheduled rule

displayNamestring

The display name of the scheduled rule

enabledboolean

Determines whether or not the scheduled rule is active

idstring required

The id of the scheduled rule

managedboolean

Determines if the scheduled rule is managed by panther

outputIDsstring[]

Destination IDs that override default alert routing based on severity

referencestring

A URL or note for additional reference material

reportsobject

reports

runbookstring

How to handle the generated alert

scheduledQueriesstring[]

the queries that this scheduled rule utilizes

severity'INFO' | 'LOW' | 'MEDIUM' | 'HIGH' | 'CRITICAL' required
summaryAttributesstring[]

A list of fields in the event to create top 5 summaries for

tagsstring[]

The tags for the scheduled rule

thresholdinteger

the number of events that must match before an alert is triggered

Response

OK response.

bodystring

The python body of the scheduled rule

createAlertboolean

Determines whether the scheduled rule should create alerts when it triggers

createdAtstring
createdByExternalstring

The text of the user-provided CreatedBy field when uploaded via CI/CD

dedupPeriodMinutesinteger

The amount of time in minutes for grouping alerts

descriptionstring

The description of the scheduled rule

displayNamestring

The display name of the scheduled rule

enabledboolean

Determines whether or not the scheduled rule is active

idstring

The id of the scheduled rule

lastModifiedstring
managedboolean

Determines if the scheduled rule is managed by panther

outputIDsstring[]

Destination IDs that override default alert routing based on severity

referencestring

A URL or note for additional reference material

reportsobject

reports

runbookstring

How to handle the generated alert

scheduledQueriesstring[]

the queries that this scheduled rule utilizes

severity'INFO' | 'LOW' | 'MEDIUM' | 'HIGH' | 'CRITICAL'
summaryAttributesstring[]

A list of fields in the event to create top 5 summaries for

tagsstring[]

The tags for the scheduled rule

thresholdinteger

the number of events that must match before an alert is triggered