> ## Documentation Index
> Fetch the complete documentation index at: https://docs.coralogix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get alert definition by alert version ID

> Returns the alert definition with the specified version ID.

Requires the following permissions:
- `alerts:ReadConfig`



## OpenAPI

````yaml openapi_v5.yaml get /alerts/alerts/v3/version-ids/{alert_version_id}
openapi: 3.0.0
info:
  title: ''
  version: 1.0.0
servers:
  - url: https://api.coralogix.com/mgmt/openapi/5
  - url: https://api.eu2.coralogix.com/mgmt/openapi/5
  - url: https://api.coralogix.us/mgmt/openapi/5
  - url: https://api.cx498.coralogix.com/mgmt/openapi/5
  - url: https://api.coralogix.in/mgmt/openapi/5
  - url: https://api.coralogixsg.com/mgmt/openapi/5
  - url: https://api.ap3.coralogix.com/mgmt/openapi/5
security:
  - apiKeyAuth: []
tags:
  - name: AI Applications Service
    description: Manage the catalog of AI applications discovered from spans.
    externalDocs:
      url: ''
  - name: AI Evaluations Service
    description: >-
      Manage AI evaluations and the custom evaluation catalog for AI
      applications.
    externalDocs:
      url: ''
  - name: API Keys Admin Service
    description: Administrative operations for API Keys management.
    externalDocs:
      url: ''
  - name: API Keys Service
    description: Manage your API Keys.
    externalDocs:
      url: ''
  - name: Actions Service
    description: View and manage your Actions.
    externalDocs:
      url: ''
  - name: Alert Scheduler Rule service
    description: Manage your alert scheduler rules.
    externalDocs:
      url: ''
  - name: Alert definitions service
    description: >-
      View and manage your alerts using alert definitions - data structures that
      contain the configuration required to create an alert.
    externalDocs:
      description: Learn more about alerts in our documentation
      url: https://coralogix.com/docs/user-guides/alerting/introduction-to-alerts/
  - name: Alert events service
    description: >-
      Get information regarding your alert events - instances of alerts being
      triggered.
    externalDocs:
      description: Learn more about alert events and incidents in our documentation.
      url: https://coralogix.com/docs/user-guides/alerting/incidents/
  - name: Case Events service
    description: Manage case events, comments, and external thread synchronization.
    externalDocs:
      url: ''
  - name: Case Settings service
    description: Manage case settings team configurations.
    externalDocs:
      url: ''
  - name: Cases notification service
    description: Track notification adjacent data for cases.
    externalDocs:
      url: ''
  - name: Cases service
    description: >-
      Manage cases throughout their lifecycle. Create, view, assign,
      acknowledge, unacknowledge, resolve, and close cases to streamline
      investigations and follow-ups.
    externalDocs:
      description: Learn more about Cases in our documentation
      url: https://coralogix.com/docs/user-guides/cases/
  - name: Connector Schema service
    description: Retrieve connector schemas for notification center integrations
    externalDocs:
      description: Learn more about connectors in our documentation
      url: >-
        https://coralogix.com/docs/user-guides/notification-center/connectors/introduction/
  - name: Connectors service
    description: >-
      View and manage your connectors - integration instances for notification
      destinations
    externalDocs:
      description: Lean more about connectors in our documentation
      url: >-
        https://coralogix.com/docs/user-guides/notification-center/connectors/introduction/
  - name: Contextual data integration service
    description: Query for contextual data integration information.
    externalDocs:
      url: ''
  - name: Custom Enrichments Service
    description: Manage your enrichments.
    externalDocs:
      url: ''
  - name: Dashboard folders service
    description: Manage your dashboard folders.
    externalDocs:
      url: ''
  - name: Dashboard service
    description: Get information about the Coralogix Dashboard catalog.
    externalDocs:
      url: ''
  - name: Data Usage Query service
    description: >-
      Query billable data usage through the public Coralogix API using daily or
      hourly bucketed aggregations over supported labels.
    externalDocs:
      url: ''
  - name: Data Usage Service
    description: A service to manage data usage metrics.
    externalDocs:
      url: ''
  - name: Enrichments Service
    description: Manage your enrichments.
    externalDocs:
      url: ''
  - name: Entities service
    description: Query information about registered entities in the notification center
    externalDocs:
      description: Lean more about the notification center in our documentation
      url: https://coralogix.com/docs/user-guides/notification-center/introduction/
  - name: Events Service
    description: A service for querying events.
    externalDocs:
      description: Learn more about alerts in our documentation
      url: https://coralogix.com/docs/user-guides/alerting/introduction-to-alerts/
  - name: Events2Metrics Service
    description: Manage your events2metrics.
    externalDocs:
      url: ''
  - name: Extension deployment service
    description: A service that enables querying for extension deployment information.
    externalDocs:
      description: Find out more about extensions in our documentation.
      url: https://coralogix.com/docs/integrations/extensions/
  - name: Extension service
    description: A service that enables querying for extension information.
    externalDocs:
      description: Learn more about extensions in our documentation.
      url: https://coralogix.com/docs/integrations/extensions/
  - name: Folders for views service
    description: Create and manage view folders.
    externalDocs:
      url: ''
  - name: Global routers service
    description: >-
      View and manage your global routers - entities that direct notifications
      to configured destinations based on conditions
    externalDocs:
      description: Lean more about global routers in our documentation
      url: >-
        https://coralogix.com/docs/user-guides/notification-center/routing/introduction/
  - name: IP access service
    description: >-
      IP access service provides the API for managing company IP access
      settings.
    externalDocs:
      url: ''
  - name: Incidents service
    description: >-
      Handle all operations related to incident management within Coralogix.
      Identify, manage, and resolve incidents efficiently through automated
      workflows and team collaboration.
    externalDocs:
      description: Find out more about incident management in our documentation
      url: https://coralogix.com/docs/user-guides/alerting/incidents/
  - name: Integration service
    description: A service that enables querying for integration information.
    externalDocs:
      description: Find out more about integrations in our documentation.
      url: https://coralogix.com/docs/integrations/getting-started/
  - name: Metrics Data Archive Service
    description: View and manage your storage targets for metrics.
    externalDocs:
      description: Find out more about archives
      url: >-
        https://coralogix.com/docs/user-guides/data-flow/s3-archive/connect-s3-archive/
  - name: Notifications testing service
    description: >-
      Test your notification center configurations including connectors,
      presets, and templates
    externalDocs:
      description: Lean more about the notification center in our documentation
      url: https://coralogix.com/docs/user-guides/notification-center/introduction/
  - name: Outgoing webhooks service
    externalDocs:
      description: Find out more about outbound webhooks in our documentation.
      url: >-
        https://coralogix.com/docs/user-guides/alerting/outbound-webhooks/generic-outbound-webhooks-alert-webhooks/
  - name: Policies Service
    description: View and manage your TCO policies
    externalDocs:
      url: ''
  - name: Presets service
    description: >-
      View and manage your presets - pre-configured templates for notification
      content rendering
    externalDocs:
      description: Lean more about presets in our documentation
      url: >-
        https://coralogix.com/docs/user-guides/notification-center/presets/introduction/
  - name: Quota Allocation Rule Set service
    description: Manage quota allocation rules for different entity types.
    externalDocs:
      url: ''
  - name: Recording Rules Service
    description: A service to manage recording rules.
    externalDocs:
      url: ''
  - name: Retentions Service
    description: View and manage retentions
    externalDocs:
      url: ''
  - name: Role Management Service
    description: Service for managing system and custom roles.
    externalDocs:
      url: ''
  - name: Rule Groups Service
    description: A service to manage rule groups.
    externalDocs:
      url: ''
  - name: SAML Configuration Service
    description: Manage your SAML configuration
    externalDocs:
      url: ''
  - name: Scopes Service
    description: A service to manage scopes
    externalDocs:
      url: ''
  - name: Slos Service
    description: A service for managing Service Level Objectives (SLOs).
    externalDocs:
      url: ''
  - name: Target Service
    description: View and manage your storage targets for logs.
    externalDocs:
      description: Find out more about archives
      url: >-
        https://coralogix.com/docs/user-guides/data-flow/s3-archive/connect-s3-archive/
  - name: Team Groups Management Service
    description: Manage Team Groups.
    externalDocs:
      url: ''
  - name: Users Management Service
    description: >-
      Manage team members (users) including creation, updates, search, and
      status management.
    externalDocs:
      url: ''
  - name: Views service
    description: Create and manage views.
    externalDocs:
      url: ''
paths:
  /alerts/alerts/v3/version-ids/{alert_version_id}:
    get:
      tags:
        - Alert definitions service
      summary: Get alert definition by alert version ID
      description: |-
        Returns the alert definition with the specified version ID.

        Requires the following permissions:
        - `alerts:ReadConfig`
      operationId: AlertDefsService_GetAlertDefByVersionId
      parameters:
        - description: Alert version ID
          in: path
          name: alert_version_id
          required: true
          schema:
            maxLength: 36
            minLength: 0
            pattern: ^[\s\S]*$
            type: string
            description: Alert version ID
            example: 123e4567-e89b-12d3-a456-426614174000
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GetAlertDefByVersionIdResponse'
          description: ''
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
          description: Bad Request
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
          description: Unauthorized request
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
          description: Internal server error
      externalDocs:
        url: ''
components:
  schemas:
    GetAlertDefByVersionIdResponse:
      title: Get alert definition by version ID response
      type: object
      properties:
        alertDef:
          $ref: '#/components/schemas/AlertDef'
      description: A response that contains an alert definition for the requested version
      externalDocs:
        url: ''
    Error:
      type: object
      properties:
        code:
          maximum: 599
          minimum: 100
          type: integer
          description: HTTP status code of the error (for example 400, 404, 500).
          format: int32
        message:
          maxLength: 4096
          minLength: 0
          pattern: ^[\s\S]*$
          type: string
          description: Human-readable description of the error.
      description: Standard error response body returned for a failed request.
    AlertDef:
      title: Alert definition
      type: object
      properties:
        alertDefProperties:
          $ref: '#/components/schemas/AlertDefProperties'
        alertVersionId:
          maxLength: 36
          minLength: 1
          pattern: ^[\s\S]*$
          type: string
          description: The old alert ID
        createdTime:
          maxLength: 64
          minLength: 0
          pattern: ^[\s\S]*$
          type: string
          description: The time when the alert definition was created
          format: date-time
          example: '2023-10-01T12:00:00.000Z'
        id:
          maxLength: 36
          minLength: 1
          pattern: >-
            ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$
          type: string
          description: The alert definition's persistent ID
          example: 123e4567-e89b-12d3-a456-426614174000
        lastTriggeredTime:
          maxLength: 64
          minLength: 0
          pattern: ^[\s\S]*$
          type: string
          description: The last time the alert definition was triggered
          format: date-time
          example: '2023-10-01T12:00:00.000Z'
        status:
          $ref: '#/components/schemas/AlertDefStatus'
        updatedTime:
          maxLength: 64
          minLength: 0
          pattern: ^[\s\S]*$
          type: string
          description: The time when the alert definition was last updated
          format: date-time
          example: '2023-10-01T12:00:00.000Z'
      description: This data structure represents an alert definition
      externalDocs:
        description: Find out more about alerts in our documentation
        url: >-
          https://coralogix.com/docs/user-guides/alerting/introduction-to-alerts/
    AlertDefProperties:
      title: Alert definition properties
      type: object
      oneOf:
        - required:
            - logsImmediate
          type: object
        - required:
            - tracingImmediate
          type: object
        - required:
            - logsThreshold
          type: object
        - required:
            - logsRatioThreshold
          type: object
        - required:
            - logsTimeRelativeThreshold
          type: object
        - required:
            - metricThreshold
          type: object
        - required:
            - tracingThreshold
          type: object
        - required:
            - flow
          type: object
        - required:
            - logsAnomaly
          type: object
        - required:
            - metricAnomaly
          type: object
        - required:
            - logsNewValue
          type: object
        - required:
            - logsUniqueCount
          type: object
        - required:
            - sloThreshold
          type: object
        - required:
            - analyticsImmediate
          type: object
        - required:
            - analyticsThreshold
          type: object
        - type: object
          not:
            anyOf:
              - required:
                  - logsImmediate
                type: object
              - required:
                  - tracingImmediate
                type: object
              - required:
                  - logsThreshold
                type: object
              - required:
                  - logsRatioThreshold
                type: object
              - required:
                  - logsTimeRelativeThreshold
                type: object
              - required:
                  - metricThreshold
                type: object
              - required:
                  - tracingThreshold
                type: object
              - required:
                  - flow
                type: object
              - required:
                  - logsAnomaly
                type: object
              - required:
                  - metricAnomaly
                type: object
              - required:
                  - logsNewValue
                type: object
              - required:
                  - logsUniqueCount
                type: object
              - required:
                  - sloThreshold
                type: object
              - required:
                  - analyticsImmediate
                type: object
              - required:
                  - analyticsThreshold
                type: object
      properties:
        activeOn:
          $ref: '#/components/schemas/ActivitySchedule'
        analyticsImmediate:
          $ref: '#/components/schemas/AnalyticsImmediateType'
        analyticsThreshold:
          $ref: '#/components/schemas/AnalyticsThresholdType'
        dataSources:
          maxItems: 1
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/AlertDefDataSource'
          description: The sources from which to sample logs
        deleted:
          type: boolean
          description: Whether the alert has been marked as deleted
          example: false
        description:
          maxLength: 3000
          minLength: 0
          pattern: ^[\s\S]*$
          type: string
          description: >-
            A detailed description of what the alert monitors and when it
            triggers
          example: Alert description
        enabled:
          type: boolean
          description: Whether the alert is currently active and monitoring
          example: true
        entityLabels:
          type: object
          additionalProperties:
            minLength: 0
            type: string
          description: Labels used to identify and categorize the alert entity
        flow:
          $ref: '#/components/schemas/FlowType'
        groupByKeys:
          maxItems: 100
          minItems: 0
          type: array
          items:
            maxLength: 1024
            minLength: 1
            pattern: ^[\s\S]*$
            type: string
            description: Keys used to group and aggregate alert data
          description: Keys used to group and aggregate alert data
          example:
            - key1
            - key2
        incidentsSettings:
          $ref: '#/components/schemas/AlertDefIncidentSettings'
        logsAnomaly:
          $ref: '#/components/schemas/LogsAnomalyType'
        logsImmediate:
          $ref: '#/components/schemas/LogsImmediateType'
        logsNewValue:
          $ref: '#/components/schemas/LogsNewValueType'
        logsRatioThreshold:
          $ref: '#/components/schemas/LogsRatioThresholdType'
        logsThreshold:
          $ref: '#/components/schemas/LogsThresholdType'
        logsTimeRelativeThreshold:
          $ref: '#/components/schemas/LogsTimeRelativeThresholdType'
        logsUniqueCount:
          $ref: '#/components/schemas/LogsUniqueCountType'
        metricAnomaly:
          $ref: '#/components/schemas/MetricAnomalyType'
        metricThreshold:
          $ref: '#/components/schemas/MetricThresholdType'
        name:
          maxLength: 512
          minLength: 1
          pattern: ^[\s\S]*$
          type: string
          description: The name of the alert definition
          example: My Alert
        notificationGroup:
          $ref: '#/components/schemas/AlertDefNotificationGroup'
        notificationGroupExcess:
          maxItems: 100
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/AlertDefNotificationGroup'
          description: Additional notification groups for alerts (deprecated)
        phantomMode:
          type: boolean
          description: Whether the alert is in phantom mode (creating incidents or not)
          example: false
        priority:
          $ref: '#/components/schemas/AlertDefPriority'
        sloThreshold:
          $ref: '#/components/schemas/SloThresholdType'
        tracingImmediate:
          $ref: '#/components/schemas/TracingImmediateType'
        tracingThreshold:
          $ref: '#/components/schemas/TracingThresholdType'
        type:
          $ref: '#/components/schemas/AlertDefType'
      description: User-configurable properties of an alert definition
      externalDocs:
        url: ''
    AlertDefStatus:
      enum:
        - ALERT_DEF_STATUS_UNSPECIFIED
        - ALERT_DEF_STATUS_ALERTING
        - ALERT_DEF_STATUS_OK
        - ALERT_DEF_STATUS_NO_DATA
      type: string
      description: Alert def status.
    ActivitySchedule:
      title: Alert activity schedule
      type: object
      properties:
        dayOfWeek:
          maxItems: 7
          minItems: 1
          type: array
          items:
            $ref: '#/components/schemas/DayOfWeek'
          description: Day of the week.
          example:
            - DAY_OF_WEEK_MONDAY_OR_UNSPECIFIED
            - DAY_OF_WEEK_TUESDAY
        endTime:
          $ref: '#/components/schemas/TimeOfDay'
        startTime:
          $ref: '#/components/schemas/TimeOfDay'
      description: >-
        Defines when an alert should be active based on days of the week and
        time windows
      externalDocs:
        url: ''
    AnalyticsImmediateType:
      title: Analytics immediate alert type
      type: object
      properties:
        dataprimeQuery:
          $ref: '#/components/schemas/DataprimeAlertQuery'
        evaluationDelayMs:
          maximum: 10800000
          minimum: 0
          type: integer
          description: The delay in milliseconds before evaluating the alert condition
          format: int32
          example: 300000
        noDataPolicy:
          $ref: '#/components/schemas/NoDataPolicy'
        timeframeMinutes:
          maximum: 2147483647
          minimum: 1
          type: integer
          description: The evaluation window duration in minutes
          format: int32
          example: 60
        useRowsAsPermutations:
          type: boolean
          description: >-
            Whether each result row is treated as a separate permutation.
            Defaults to false for immediate alerts to avoid high-cardinality
            alerts by mistake.
          example: false
      description: >-
        Configuration for analytics alerts that fire immediately when a
        DataPrime query returns a result
      externalDocs:
        url: ''
    AnalyticsThresholdType:
      title: Analytics threshold alert type
      type: object
      properties:
        dataprimeQuery:
          $ref: '#/components/schemas/DataprimeAlertQuery'
        evaluationDelayMs:
          maximum: 10800000
          minimum: 0
          type: integer
          description: The delay in milliseconds before evaluating the alert condition
          format: int32
          example: 300000
        noDataPolicy:
          $ref: '#/components/schemas/NoDataPolicy'
        operator:
          $ref: '#/components/schemas/AnalyticsThresholdOperator'
        rules:
          maxItems: 5
          minItems: 1
          type: array
          items:
            $ref: '#/components/schemas/AnalyticsThresholdRule'
          description: The per-priority threshold rules
        targetColumn:
          maxLength: 255
          minLength: 0
          pattern: ^[\s\S]*$
          type: string
          description: The name of the numeric result column to compare
          example: error_count
        timeframeMinutes:
          maximum: 2147483647
          minimum: 1
          type: integer
          description: The evaluation window duration in minutes
          format: int32
          example: 60
        useRowsAsPermutations:
          type: boolean
          description: >-
            Whether each result row is treated as a separate permutation.
            Defaults to true for threshold alerts as permutation count is easier
            to estimate.
          example: true
      description: >-
        Configuration for alerts that fire when a numeric column in a DataPrime
        query result violates a threshold
      externalDocs:
        url: ''
    AlertDefDataSource:
      type: object
      properties:
        dataSet:
          maxLength: 300
          minLength: 1
          pattern: ^[\s\S]*$
          type: string
          description: File name of the dataset
        dataSpace:
          maxLength: 50
          minLength: 1
          pattern: ^[\s\S]*$
          type: string
          description: Folder name of the datasource
    FlowType:
      title: Flow alert type
      type: object
      properties:
        enforceSuppression:
          type: boolean
          description: The enforce suppression.
        stages:
          maxItems: 30
          minItems: 1
          type: array
          items:
            $ref: '#/components/schemas/FlowStages'
          description: The stages of the flow alert.
      description: Configuration for flow-based alerts with multiple stages
      externalDocs:
        description: Learn more about flow alerts in our documentation
        url: >-
          https://coralogix.com/docs/user-guides/alerting/create-an-alert/flow-alerts/
    AlertDefIncidentSettings:
      title: Alert definition incident settings
      type: object
      properties:
        minutes:
          maximum: 10080
          minimum: 1
          type: integer
          description: The time in minutes before the alert can be retriggered
          format: int64
          example: 30
        notifyOn:
          $ref: '#/components/schemas/NotifyOn'
      description: Alert def incident settings.
      externalDocs:
        url: ''
    LogsAnomalyType:
      title: Log-based anomaly alert type
      type: object
      properties:
        anomalyAlertSettings:
          $ref: '#/components/schemas/AnomalyAlertSettings'
        evaluationDelayMs:
          maximum: 10800000
          minimum: 0
          type: integer
          description: The delay in milliseconds before evaluating the alert condition
          format: int32
          example: 60000
        logsFilter:
          $ref: '#/components/schemas/v3.LogsFilter'
        notificationPayloadFilter:
          minItems: 0
          type: array
          items:
            minLength: 0
            type: string
            description: >-
              The filter to specify which fields to include in the notification
              payload
          description: >-
            The filter to specify which fields to include in the notification
            payload
          example:
            - obj.field
        rules:
          maxItems: 1
          minItems: 1
          type: array
          items:
            $ref: '#/components/schemas/LogsAnomalyRule'
          description: The rules for the log anomaly alert
      description: Configuration for alerts triggered by anomalous log patterns
      externalDocs:
        description: Learn more about logs anomaly alerts in our documentation
        url: >-
          https://coralogix.com/docs/user-guides/alerting/create-an-alert/logs/anomaly-detection-alerts/
    LogsImmediateType:
      title: Logs immediate alert type
      type: object
      properties:
        logsFilter:
          $ref: '#/components/schemas/v3.LogsFilter'
        notificationPayloadFilter:
          minItems: 0
          type: array
          items:
            minLength: 0
            type: string
            description: The notification payload filter.
          description: The notification payload filter.
          example:
            - obj.field
      description: >-
        Configuration for immediate alerts triggered on log entries matching
        specific filters.
      externalDocs:
        description: Learn more about logs immediate alerts in our documentation
        url: >-
          https://coralogix.com/docs/user-guides/alerting/create-an-alert/logs/immediate-notifications/
    LogsNewValueType:
      title: Log-based new value alert type
      type: object
      properties:
        logsFilter:
          $ref: '#/components/schemas/v3.LogsFilter'
        notificationPayloadFilter:
          minItems: 0
          type: array
          items:
            minLength: 0
            type: string
            description: >-
              The filter to specify which fields to include in the notification
              payload.
          description: >-
            The filter to specify which fields to include in the notification
            payload.
          example:
            - obj.field
        rules:
          maxItems: 1
          minItems: 1
          type: array
          items:
            $ref: '#/components/schemas/LogsNewValueRule'
          description: The rules for the log new value alert.
      description: Configuration for alerts triggered by new values appearing in logs
      externalDocs:
        url: ''
    LogsRatioThresholdType:
      title: Log-based ratio threshold alert type
      type: object
      properties:
        denominator:
          $ref: '#/components/schemas/v3.LogsFilter'
        denominatorAlias:
          maxLength: 200
          minLength: 0
          type: string
          description: The alias for the denominator filter, used for display purposes
          example: denominator_alias
        evaluationDelayMs:
          maximum: 10800000
          minimum: 0
          type: integer
          description: The delay in milliseconds before evaluating the alert condition
          format: int32
          example: 60000
        groupByFor:
          $ref: '#/components/schemas/LogsRatioGroupByFor'
        ignoreInfinity:
          type: boolean
          description: The configuration for ignoring infinity values in the ratio
          example: true
        notificationPayloadFilter:
          minItems: 0
          type: array
          items:
            minLength: 0
            type: string
            description: The notification payload filter.
          description: The notification payload filter.
          example:
            - obj.field
        numerator:
          $ref: '#/components/schemas/v3.LogsFilter'
        numeratorAlias:
          maxLength: 200
          minLength: 0
          type: string
          description: The alias for the numerator filter, used for display purposes
          example: numerator_alias
        rules:
          maxItems: 5
          minItems: 1
          type: array
          items:
            $ref: '#/components/schemas/LogsRatioRules'
          description: The rules for the ratio alert
        undetectedValuesManagement:
          $ref: '#/components/schemas/v3.UndetectedValuesManagement'
      description: Configuration for alerts based on the ratio between two log queries
      externalDocs:
        description: Learn more about logs ratio alerts in our documentation
        url: >-
          https://coralogix.com/docs/user-guides/alerting/create-an-alert/logs/ratio-alerts/
    LogsThresholdType:
      title: Log-based threshold alert type
      type: object
      properties:
        evaluationDelayMs:
          maximum: 10800000
          minimum: 0
          type: integer
          description: The delay in milliseconds before evaluating the alert condition
          format: int32
          example: 60000
        logsFilter:
          $ref: '#/components/schemas/v3.LogsFilter'
        noDataPolicy:
          $ref: '#/components/schemas/NoDataPolicy'
        notificationPayloadFilter:
          minItems: 0
          type: array
          items:
            minLength: 0
            type: string
            description: >-
              The filter to specify which fields to include in the notification
              payload
          description: >-
            The filter to specify which fields to include in the notification
            payload
          example:
            - obj.field
        rules:
          maxItems: 5
          minItems: 1
          type: array
          items:
            $ref: '#/components/schemas/LogsThresholdRule'
          description: The rules for the threshold alert
        undetectedValuesManagement:
          $ref: '#/components/schemas/v3.UndetectedValuesManagement'
      description: >-
        Configuration for alerts triggered when log counts exceed or fall below
        specified thresholds
      externalDocs:
        description: Learn more about log-based threshold alerts in our documentation
        url: >-
          https://coralogix.com/docs/user-guides/alerting/create-an-alert/logs/threshold-alerts/
    LogsTimeRelativeThresholdType:
      title: Log-based time-relative threshold alert type
      type: object
      properties:
        evaluationDelayMs:
          maximum: 10800000
          minimum: 0
          type: integer
          description: The delay in milliseconds before evaluating the alert condition
          format: int32
          example: 60000
        ignoreInfinity:
          type: boolean
          description: Ignore infinity values in the alert
          example: true
        logsFilter:
          $ref: '#/components/schemas/v3.LogsFilter'
        notificationPayloadFilter:
          minItems: 0
          type: array
          items:
            minLength: 0
            type: string
            description: The notification payload filter.
          description: The notification payload filter.
          example:
            - obj.field
        rules:
          maxItems: 5
          minItems: 1
          type: array
          items:
            $ref: '#/components/schemas/LogsTimeRelativeRule'
          description: The rules for the time-relative alert
        undetectedValuesManagement:
          $ref: '#/components/schemas/v3.UndetectedValuesManagement'
      description: >-
        Configuration for alerts that are triggered when a fixed ratio reaches a
        set threshold compared to a past time frame.
      externalDocs:
        description: Learn more about log-based, time-relative alerts in our documentation
        url: >-
          https://coralogix.com/docs/user-guides/alerting/create-an-alert/logs/time-relative-alerts/
    LogsUniqueCountType:
      title: Log-based unique count alert type
      type: object
      properties:
        logsFilter:
          $ref: '#/components/schemas/v3.LogsFilter'
        maxUniqueCountPerGroupByKey:
          maxLength: 20
          minLength: 1
          pattern: ^-?[0-9]+$
          type: string
          description: The maximum unique count per group by key
          example: '100'
        notificationPayloadFilter:
          minItems: 0
          type: array
          items:
            minLength: 0
            type: string
            description: >-
              The filter to specify which fields to include in the notification
              payload
          description: >-
            The filter to specify which fields to include in the notification
            payload
          example:
            - obj.field
        rules:
          maxItems: 1
          minItems: 1
          type: array
          items:
            $ref: '#/components/schemas/LogsUniqueCountRule'
          description: The rules for the log unique count alert
        uniqueCountKeypath:
          minLength: 1
          type: string
          description: The keypath in the logs to be used for unique count
          example: obj.field
      description: Configuration for alerts based on unique value counts in logs
      externalDocs:
        description: Learn more about log-based, unique count alerts in our documentation
        url: >-
          https://coralogix.com/docs/user-guides/alerting/create-an-alert/logs/unique-count-alerts/
    MetricAnomalyType:
      title: Metric-based anomaly alert type
      type: object
      properties:
        anomalyAlertSettings:
          $ref: '#/components/schemas/AnomalyAlertSettings'
        evaluationDelayMs:
          maximum: 10800000
          minimum: 0
          type: integer
          description: The delay in milliseconds before evaluating the alert condition
          format: int32
          example: 60000
        metricFilter:
          $ref: '#/components/schemas/MetricFilter'
        rules:
          maxItems: 1
          minItems: 1
          type: array
          items:
            $ref: '#/components/schemas/MetricAnomalyRule'
          description: The rules for the metric anomaly alert.
      description: Configuration for alerts triggered by anomalous metric patterns
      externalDocs:
        description: Learn more about metric-based anomaly alerts in our documentation
        url: >-
          https://coralogix.com/docs/user-guides/alerting/create-an-alert/metrics/anomaly-detection-alerts/
    MetricThresholdType:
      title: Metric-based threshold alert type
      type: object
      properties:
        evaluationDelayMs:
          maximum: 10800000
          minimum: 0
          type: integer
          description: The delay in milliseconds before evaluating the alert condition
          format: int32
          example: 60000
        metricFilter:
          $ref: '#/components/schemas/MetricFilter'
        missingValues:
          $ref: '#/components/schemas/MetricMissingValues'
        noDataPolicy:
          $ref: '#/components/schemas/NoDataPolicy'
        rules:
          maxItems: 5
          minItems: 1
          type: array
          items:
            $ref: '#/components/schemas/MetricThresholdRule'
          description: The rules for the metric threshold alert
        undetectedValuesManagement:
          $ref: '#/components/schemas/v3.UndetectedValuesManagement'
      description: Configuration for alerts based on metric threshold violations
      externalDocs:
        description: Learn more about metric-based threshold alerts in our documentation
        url: >-
          https://coralogix.com/docs/user-guides/alerting/create-an-alert/metrics/threshold-alerts/
    AlertDefNotificationGroup:
      title: Alert definition notification group
      type: object
      properties:
        destinations:
          maxItems: 100
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/NotificationDestination'
          description: The destinations for notifications.  (Notification Center feature)
        groupByKeys:
          maxItems: 100
          minItems: 0
          type: array
          items:
            maxLength: 1024
            minLength: 1
            pattern: ^[\s\S]*$
            type: string
            description: The keys to group the alerts by
          description: The keys to group the alerts by
          example:
            - key1
            - key2
        router:
          $ref: '#/components/schemas/NotificationRouter'
        webhooks:
          maxItems: 100
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/AlertDefWebhooksSettings'
          description: The settings for webhooks associated with the alert definition
      description: Alert def notification group.
      externalDocs:
        url: ''
    AlertDefPriority:
      enum:
        - ALERT_DEF_PRIORITY_P5_OR_UNSPECIFIED
        - ALERT_DEF_PRIORITY_P4
        - ALERT_DEF_PRIORITY_P3
        - ALERT_DEF_PRIORITY_P2
        - ALERT_DEF_PRIORITY_P1
      type: string
      description: Alert def priority.
    SloThresholdType:
      title: SLO Threshold Type
      type: object
      oneOf:
        - required:
            - errorBudget
          type: object
        - required:
            - burnRate
          type: object
        - type: object
          not:
            anyOf:
              - required:
                  - errorBudget
                type: object
              - required:
                  - burnRate
                type: object
      properties:
        burnRate:
          $ref: '#/components/schemas/BurnRateThreshold'
        errorBudget:
          $ref: '#/components/schemas/ErrorBudgetThreshold'
        sloDefinition:
          $ref: '#/components/schemas/v3.SloDefinition'
      description: SLO threshold type definition
      externalDocs:
        url: ''
    TracingImmediateType:
      title: Trace-based immediate alert type
      type: object
      properties:
        notificationPayloadFilter:
          minItems: 0
          type: array
          items:
            minLength: 0
            type: string
            description: Notification payload field filter
          description: Notification payload field filter
          example:
            - obj.field
        tracingFilter:
          $ref: '#/components/schemas/TracingFilter'
      description: Configuration for immediate alerts triggered on trace entries
      externalDocs:
        description: Learn more about trace-based alerts in our documentation.
        url: >-
          https://coralogix.com/docs/user-guides/alerting/create-an-alert/traces/tracing-alerts/
    TracingThresholdType:
      title: Trace-based threshold alert type
      type: object
      properties:
        notificationPayloadFilter:
          minItems: 0
          type: array
          items:
            minLength: 0
            type: string
            description: Notification payload field filter
          description: Notification payload field filter
          example:
            - obj.field
        rules:
          maxItems: 1
          minItems: 1
          type: array
          items:
            $ref: '#/components/schemas/TracingThresholdRule'
          description: The rules for the trace threshold alert.
        tracingFilter:
          $ref: '#/components/schemas/TracingFilter'
      description: Configuration for alerts based on trace count thresholds
      externalDocs:
        description: Learn more about trace-based alerts in our documentation
        url: >-
          https://coralogix.com/docs/user-guides/alerting/create-an-alert/traces/tracing-alerts/
    AlertDefType:
      enum:
        - ALERT_DEF_TYPE_LOGS_IMMEDIATE_OR_UNSPECIFIED
        - ALERT_DEF_TYPE_LOGS_THRESHOLD
        - ALERT_DEF_TYPE_LOGS_ANOMALY
        - ALERT_DEF_TYPE_LOGS_RATIO_THRESHOLD
        - ALERT_DEF_TYPE_LOGS_NEW_VALUE
        - ALERT_DEF_TYPE_LOGS_UNIQUE_COUNT
        - ALERT_DEF_TYPE_LOGS_TIME_RELATIVE_THRESHOLD
        - ALERT_DEF_TYPE_METRIC_THRESHOLD
        - ALERT_DEF_TYPE_METRIC_ANOMALY
        - ALERT_DEF_TYPE_TRACING_IMMEDIATE
        - ALERT_DEF_TYPE_TRACING_THRESHOLD
        - ALERT_DEF_TYPE_FLOW
        - ALERT_DEF_TYPE_SLO_THRESHOLD
        - ALERT_DEF_TYPE_ANALYTICS_IMMEDIATE
        - ALERT_DEF_TYPE_ANALYTICS_THRESHOLD
      type: string
      description: Alert def type.
    DayOfWeek:
      enum:
        - DAY_OF_WEEK_MONDAY_OR_UNSPECIFIED
        - DAY_OF_WEEK_TUESDAY
        - DAY_OF_WEEK_WEDNESDAY
        - DAY_OF_WEEK_THURSDAY
        - DAY_OF_WEEK_FRIDAY
        - DAY_OF_WEEK_SATURDAY
        - DAY_OF_WEEK_SUNDAY
      type: string
    TimeOfDay:
      title: Time of day
      type: object
      properties:
        hours:
          maximum: 23
          minimum: 0
          type: integer
          description: The hours.
          format: int32
          example: 14
        minutes:
          maximum: 59
          minimum: 0
          type: integer
          description: The minutes.
          format: int32
          example: 30
      description: Represents a specific time in a 24-hour format
      externalDocs:
        url: ''
    DataprimeAlertQuery:
      title: DataPrime alert query
      type: object
      properties:
        query:
          maxLength: 65535
          minLength: 1
          pattern: ^[\s\S]*$
          type: string
          description: The DataPrime query string
          example: >-
            source logs | filter severity == 'error' | count_agg_key by
            applicationName
      description: A DataPrime query
      externalDocs:
        url: ''
    NoDataPolicy:
      type: object
      properties:
        autoRetireSeconds:
          minimum: 60
          type: integer
          description: >-
            The timeframe in seconds for auto retiring values that were detected
            as no-data. accepts only multiples of 60 seconds
          format: int32
          example: 3600
        state:
          $ref: '#/components/schemas/NoDataPolicyState'
      description: No data policy.
      externalDocs:
        url: ''
    AnalyticsThresholdOperator:
      enum:
        - ANALYTICS_THRESHOLD_OPERATOR_MORE_THAN_OR_UNSPECIFIED
        - ANALYTICS_THRESHOLD_OPERATOR_LESS_THAN
        - ANALYTICS_THRESHOLD_OPERATOR_MORE_THAN_OR_EQUALS
        - ANALYTICS_THRESHOLD_OPERATOR_LESS_THAN_OR_EQUALS
        - ANALYTICS_THRESHOLD_OPERATOR_EQUALS
      type: string
      description: The comparison operator applied to analytics threshold rules.
    AnalyticsThresholdRule:
      title: Analytics threshold rule
      type: object
      properties:
        condition:
          $ref: '#/components/schemas/AnalyticsThresholdRuleCondition'
        override:
          $ref: '#/components/schemas/AlertDefOverride'
      description: A rule that defines a threshold condition and its priority override
      externalDocs:
        url: ''
    FlowStages:
      title: Flow stages
      type: object
      properties:
        flowStagesGroups:
          $ref: '#/components/schemas/FlowStagesGroups'
        timeframeMs:
          maxLength: 20
          minLength: 1
          pattern: ^-?[0-9]+$
          type: string
          description: The timeframe ms.
        timeframeType:
          $ref: '#/components/schemas/TimeframeType'
      description: Defines stages in a flow alert
      externalDocs:
        url: ''
    NotifyOn:
      enum:
        - NOTIFY_ON_TRIGGERED_ONLY_UNSPECIFIED
        - NOTIFY_ON_TRIGGERED_AND_RESOLVED
      type: string
      description: Notify on.
    AnomalyAlertSettings:
      title: Anomaly alert settings
      type: object
      properties:
        percentageOfDeviation:
          minimum: 0
          type: number
          description: >-
            The percentage of deviation from the baseline for triggering the
            alert.
          format: float
      description: Common settings for anomaly-based alerts.
      externalDocs:
        url: ''
    v3.LogsFilter:
      title: Log filter
      type: object
      properties:
        simpleFilter:
          $ref: '#/components/schemas/LogsSimpleFilter'
      description: Filter configuration for log-based alerts
      externalDocs:
        url: ''
    LogsAnomalyRule:
      title: Log-based anomaly rule
      type: object
      properties:
        condition:
          $ref: '#/components/schemas/LogsAnomalyCondition'
      description: Defines a rule for detecting log anomalies
      externalDocs:
        url: ''
    LogsNewValueRule:
      title: Log-based new value rule
      type: object
      properties:
        condition:
          $ref: '#/components/schemas/LogsNewValueCondition'
      description: Defines the condition for detecting new values in logs
      externalDocs:
        url: ''
    LogsRatioGroupByFor:
      enum:
        - LOGS_RATIO_GROUP_BY_FOR_BOTH_OR_UNSPECIFIED
        - LOGS_RATIO_GROUP_BY_FOR_NUMERATOR_ONLY
        - LOGS_RATIO_GROUP_BY_FOR_DENUMERATOR_ONLY
      type: string
      description: Logs ratio group by for.
    LogsRatioRules:
      title: Log-based ratio rules
      type: object
      properties:
        condition:
          $ref: '#/components/schemas/LogsRatioCondition'
        override:
          $ref: '#/components/schemas/AlertDefOverride'
      description: Defines the rules for log-based ratio alerts
      externalDocs:
        url: ''
    v3.UndetectedValuesManagement:
      title: Undetected value management
      type: object
      properties:
        autoRetireTimeframe:
          $ref: '#/components/schemas/v3.AutoRetireTimeframe'
        triggerUndetectedValues:
          type: boolean
          description: Should trigger the alert when undetected values are detected
          example: true
      description: Configuration for handling undetected values in alerts
      externalDocs:
        url: ''
    LogsThresholdRule:
      title: Logs Threshold Rule
      type: object
      properties:
        condition:
          $ref: '#/components/schemas/LogsThresholdCondition'
        override:
          $ref: '#/components/schemas/AlertDefOverride'
      description: >-
        LogsThresholdRule is a message that defines a rule for log-based
        threshold alerts.
      externalDocs:
        url: ''
    LogsTimeRelativeRule:
      title: Logs Time Relative Rule
      type: object
      properties:
        condition:
          $ref: '#/components/schemas/LogsTimeRelativeCondition'
        override:
          $ref: '#/components/schemas/AlertDefOverride'
      description: >-
        LogsTimeRelativeRule is a message that defines a rule for log-based
        time-relative alerts
      externalDocs:
        url: ''
    LogsUniqueCountRule:
      title: Log-based unique count rule
      type: object
      properties:
        condition:
          $ref: '#/components/schemas/LogsUniqueCountCondition'
      description: Defines the rule for detecting unique counts in logs
      externalDocs:
        url: ''
    MetricFilter:
      title: Metric filter configuration in alerts
      type: object
      properties:
        promql:
          maxLength: 65535
          minLength: 1
          type: string
          description: A PromQL filter for metrics
          example: avg_over_time(metric_name[5m]) > 10
      description: Metric filter.
      externalDocs:
        url: ''
    MetricAnomalyRule:
      title: Metric-based anomaly rule
      type: object
      properties:
        condition:
          $ref: '#/components/schemas/MetricAnomalyCondition'
      description: A rule for metric-based anomaly detection alerts
      externalDocs:
        url: ''
    MetricMissingValues:
      title: Metric Missing Values Configuration
      type: object
      oneOf:
        - required:
            - replaceWithZero
          type: object
        - required:
            - minNonNullValuesPct
          type: object
        - type: object
          not:
            anyOf:
              - required:
                  - replaceWithZero
                type: object
              - required:
                  - minNonNullValuesPct
                type: object
      properties:
        minNonNullValuesPct:
          maximum: 100
          minimum: 0
          type: integer
          description: >-
            If set, specifies the minimum percentage of non-null values required
            for the alert to be triggered
          format: int64
          example: 80
        replaceWithZero:
          type: boolean
          description: If set to true, missing values will be replaced with zero
          example: true
      description: Configuration for handling missing values in metric threshold alerts.
      externalDocs:
        url: ''
    MetricThresholdRule:
      title: Metric Threshold Rule
      type: object
      properties:
        condition:
          $ref: '#/components/schemas/MetricThresholdCondition'
        override:
          $ref: '#/components/schemas/AlertDefOverride'
      description: Defines a rule for metric-based threshold alerts
      externalDocs:
        url: ''
    NotificationDestination:
      title: Notification destination configuration
      type: object
      properties:
        connectorId:
          minLength: 0
          type: string
          description: The connector ID used to send notifications
          example: connector_id_example
        notifyOn:
          $ref: '#/components/schemas/NotifyOn'
        presetId:
          minLength: 0
          type: string
          description: Optional preset ID for the notification destination
          example: preset_id_example
        resolvedRouteOverrides:
          $ref: '#/components/schemas/NotificationRouting'
        retriggeringPeriodMinutes:
          minimum: 0
          type: integer
          description: >-
            The time in minutes before a new notification is sent for this
            destination
          format: int64
          example: 600
        triggeredRoutingOverrides:
          $ref: '#/components/schemas/NotificationRouting'
      description: Configuration for where and how alert notifications should be sent
      externalDocs:
        description: Learn more about alert notification destinations in our documentation
        url: >-
          https://coralogix.com/docs/user-guides/alerting/configure-notifications/destinations/
    NotificationRouter:
      title: Notification router
      type: object
      properties:
        id:
          minLength: 0
          type: string
          description: The ID of the notification router
          example: 123e4567-e89b-12d3-a456-426614174000
        notifyOn:
          $ref: '#/components/schemas/NotifyOn'
      description: Configuration for routing notifications
      externalDocs:
        url: ''
    AlertDefWebhooksSettings:
      title: Alert definition webhook settings
      type: object
      properties:
        integration:
          $ref: '#/components/schemas/v3.IntegrationType'
        minutes:
          maximum: 10080
          minimum: 1
          type: integer
          description: The time in minutes before the alert can be retriggered
          format: int64
          example: 15
        notifyOn:
          $ref: '#/components/schemas/NotifyOn'
      description: Configuration for webhook notifications for an alert
      externalDocs:
        url: ''
    BurnRateThreshold:
      title: Burn Rate Threshold
      type: object
      oneOf:
        - required:
            - dual
          type: object
        - required:
            - single
          type: object
        - type: object
          not:
            anyOf:
              - required:
                  - dual
                type: object
              - required:
                  - single
                type: object
      properties:
        dual:
          $ref: '#/components/schemas/BurnRateTypeDual'
        rules:
          maxItems: 5
          minItems: 1
          type: array
          items:
            $ref: '#/components/schemas/SloThresholdRule'
          description: The rules for the burn rate threshold
        single:
          $ref: '#/components/schemas/BurnRateTypeSingle'
      description: Burn rate threshold definition
      externalDocs:
        url: ''
    ErrorBudgetThreshold:
      title: Error Budget Threshold
      type: object
      properties:
        rules:
          maxItems: 5
          minItems: 1
          type: array
          items:
            $ref: '#/components/schemas/SloThresholdRule'
          description: The rules for the error budget threshold
      description: Error budget threshold definition
      externalDocs:
        url: ''
    v3.SloDefinition:
      title: SLO Definition
      type: object
      properties:
        sloId:
          maxLength: 36
          minLength: 1
          type: string
          description: The SLO ID
          example: 123e4567-e89b-12d3-a456-426614174000
      description: Configuration for SLO definition
      externalDocs:
        url: ''
    TracingFilter:
      title: Tracing filter
      type: object
      properties:
        simpleFilter:
          $ref: '#/components/schemas/TracingSimpleFilter'
      description: Filter configuration for tracing-based alerts
      externalDocs:
        url: ''
    TracingThresholdRule:
      title: Trace Threshold Rule
      type: object
      properties:
        condition:
          $ref: '#/components/schemas/TracingThresholdCondition'
      description: A rule for trace-based threshold alerts
      externalDocs:
        url: ''
    NoDataPolicyState:
      enum:
        - NO_DATA_POLICY_STATE_UNSPECIFIED
        - NO_DATA_POLICY_STATE_OK
        - NO_DATA_POLICY_STATE_ALERTING
        - NO_DATA_POLICY_STATE_KEEP_LAST
        - NO_DATA_POLICY_STATE_NO_DATA
      type: string
      description: No data policy state.
    AnalyticsThresholdRuleCondition:
      title: Analytics threshold rule condition
      type: object
      properties:
        threshold:
          type: number
          description: The threshold value to compare against
          format: double
          example: 100
      description: Defines the threshold value to compare against
      externalDocs:
        url: ''
    AlertDefOverride:
      title: Alert definition priority update
      type: object
      properties:
        priority:
          $ref: '#/components/schemas/AlertDefPriority'
      description: Alert def override.
      externalDocs:
        url: ''
    FlowStagesGroups:
      title: Flow stage groups
      type: object
      properties:
        groups:
          maxItems: 30
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/FlowStagesGroup'
          description: List of groups.
      description: Groups of stages in a flow alert
      externalDocs:
        url: ''
    TimeframeType:
      enum:
        - TIMEFRAME_TYPE_UNSPECIFIED
        - TIMEFRAME_TYPE_UP_TO
      type: string
      description: Timeframe type.
    LogsSimpleFilter:
      title: Simple log filter
      type: object
      properties:
        labelFilters:
          $ref: '#/components/schemas/LabelFilters'
        luceneQuery:
          minLength: 0
          type: string
          description: The lucene query.
      description: Basic filter configuration using a Lucene query and label filters
      externalDocs:
        url: ''
    LogsAnomalyCondition:
      title: Log-based anomaly condition
      type: object
      properties:
        conditionType:
          $ref: '#/components/schemas/LogsAnomalyConditionType'
        minimumThreshold:
          type: number
          description: The threshold value for the alert condition
          format: double
          example: 10
        timeWindow:
          $ref: '#/components/schemas/LogsTimeWindow'
      description: Defines conditions for detecting log anomalies
      externalDocs:
        url: ''
    LogsNewValueCondition:
      title: Log-based new value condition
      type: object
      properties:
        keypathToTrack:
          minLength: 0
          type: string
          description: The keypath to track for new values
          example: metadata.field
        timeWindow:
          $ref: '#/components/schemas/LogsNewValueTimeWindow'
      description: Defines conditions for detecting new values in logs
      externalDocs:
        url: ''
    LogsRatioCondition:
      title: Log-based ratio condition
      type: object
      properties:
        conditionType:
          $ref: '#/components/schemas/LogsRatioConditionType'
        threshold:
          minimum: 0
          type: number
          description: The threshold value for the alert condition
          format: double
          example: 10
        timeWindow:
          $ref: '#/components/schemas/LogsRatioTimeWindow'
      description: Defines conditions for ratio-based alerts
      externalDocs:
        url: ''
    v3.AutoRetireTimeframe:
      enum:
        - AUTO_RETIRE_TIMEFRAME_NEVER_OR_UNSPECIFIED
        - AUTO_RETIRE_TIMEFRAME_MINUTES_5
        - AUTO_RETIRE_TIMEFRAME_MINUTES_10
        - AUTO_RETIRE_TIMEFRAME_HOUR_1
        - AUTO_RETIRE_TIMEFRAME_HOURS_2
        - AUTO_RETIRE_TIMEFRAME_HOURS_6
        - AUTO_RETIRE_TIMEFRAME_HOURS_12
        - AUTO_RETIRE_TIMEFRAME_HOURS_24
      type: string
      description: Auto retire timeframe.
    LogsThresholdCondition:
      title: Logs Threshold Condition
      type: object
      properties:
        conditionType:
          $ref: '#/components/schemas/LogsThresholdConditionType'
        threshold:
          minimum: 0
          type: number
          description: The threshold value for the alert condition
          format: double
          example: 100
        timeWindow:
          $ref: '#/components/schemas/LogsTimeWindow'
      description: >-
        LogsThresholdCondition is a message that defines the condition for
        log-based threshold alerts.
      externalDocs:
        url: ''
    LogsTimeRelativeCondition:
      title: Log-based time-relative condition
      type: object
      properties:
        comparedTo:
          $ref: '#/components/schemas/LogsTimeRelativeComparedTo'
        conditionType:
          $ref: '#/components/schemas/LogsTimeRelativeConditionType'
        threshold:
          minimum: 0
          type: number
          description: The threshold value for the alert condition.
          format: double
      description: Defines conditions for time-relative comparison alerts
      externalDocs:
        url: ''
    LogsUniqueCountCondition:
      title: Logs unique count condition
      type: object
      properties:
        maxUniqueCount:
          maxLength: 20
          minLength: 1
          pattern: ^-?[0-9]+$
          type: string
          description: The maximum unique count
          example: '100'
        timeWindow:
          $ref: '#/components/schemas/LogsUniqueValueTimeWindow'
      description: Defines conditions for unique count alerts
      externalDocs:
        url: ''
    MetricAnomalyCondition:
      title: Metric-based anomaly condition
      type: object
      properties:
        conditionType:
          $ref: '#/components/schemas/MetricAnomalyConditionType'
        forOverPct:
          maximum: 100
          minimum: 0
          type: integer
          description: >-
            The percentage of the metric that must exceed the threshold to
            trigger the alert
          format: int64
          example: 20
        minNonNullValuesPct:
          maximum: 100
          minimum: 0
          type: integer
          description: The percentage of non-null values required to trigger the alert
          format: int64
          example: 10
        ofTheLast:
          $ref: '#/components/schemas/MetricTimeWindow'
        threshold:
          type: number
          description: The threshold value for the alert condition
          format: double
          example: 10
      description: Metric anomaly condition.
      externalDocs:
        url: ''
    MetricThresholdCondition:
      title: Metric Threshold Condition
      type: object
      properties:
        conditionType:
          $ref: '#/components/schemas/MetricThresholdConditionType'
        forOverPct:
          maximum: 100
          minimum: 0
          type: integer
          description: >-
            The percentage of values that must exceed the threshold to trigger
            the alert
          format: int64
          example: 80
        ofTheLast:
          $ref: '#/components/schemas/MetricTimeWindow'
        threshold:
          type: number
          description: The threshold value for the alert condition
          format: double
          example: 100
      description: Defines conditions for metric threshold alerts
      externalDocs:
        url: ''
    NotificationRouting:
      title: Notification routing
      type: object
      properties:
        configOverrides:
          $ref: '#/components/schemas/v3.SourceOverrides'
      description: Notification routing.
      externalDocs:
        url: ''
    v3.IntegrationType:
      title: Integration type
      type: object
      oneOf:
        - required:
            - integrationId
          type: object
        - required:
            - recipients
          type: object
        - type: object
          not:
            anyOf:
              - required:
                  - integrationId
                type: object
              - required:
                  - recipients
                type: object
      properties:
        integrationId:
          minimum: 0
          type: integer
          description: The integration ID for the notification
          format: int64
          example: 123
        recipients:
          $ref: '#/components/schemas/Recipients'
      description: Defines the type of integration to use for notifications
      externalDocs:
        url: ''
    BurnRateTypeDual:
      title: Burn Rate Type Dual
      type: object
      properties:
        timeDuration:
          $ref: '#/components/schemas/TimeDuration'
      description: Burn rate type dual definition
      externalDocs:
        url: ''
    SloThresholdRule:
      title: SLO Threshold Rule
      type: object
      properties:
        condition:
          $ref: '#/components/schemas/SloThresholdCondition'
        override:
          $ref: '#/components/schemas/AlertDefOverride'
      description: SLO threshold rule definition
      externalDocs:
        url: ''
    BurnRateTypeSingle:
      title: Burn Rate Type Single
      type: object
      properties:
        timeDuration:
          $ref: '#/components/schemas/TimeDuration'
      description: Burn rate type single definition
      externalDocs:
        url: ''
    TracingSimpleFilter:
      title: Simple tracing filter
      type: object
      properties:
        latencyThresholdMs:
          maxLength: 20
          minLength: 1
          pattern: ^[0-9]+$
          type: string
          description: The latency threshold to filter traces in milliseconds
          example: '1000'
        tracingLabelFilters:
          $ref: '#/components/schemas/TracingLabelFilters'
      description: Basic filter configuration using a latency threshold and label filters
      externalDocs:
        url: ''
    TracingThresholdCondition:
      title: Trace-based alert threshold condition
      type: object
      properties:
        conditionType:
          $ref: '#/components/schemas/TracingThresholdConditionType'
        spanAmount:
          minimum: 0
          type: number
          description: The threshold value for the alert condition
          format: double
          example: 100
        timeWindow:
          $ref: '#/components/schemas/TracingTimeWindow'
      description: Tracing threshold condition.
      externalDocs:
        url: ''
    FlowStagesGroup:
      title: Flow stage group
      type: object
      properties:
        alertDefs:
          maxItems: 30
          minItems: 1
          type: array
          items:
            $ref: '#/components/schemas/FlowStagesGroupsAlertDefs'
          description: The alert definitions for the flow stage group.
        alertsOp:
          $ref: '#/components/schemas/AlertsOp'
        nextOp:
          $ref: '#/components/schemas/NextOp'
      description: Defines a group of stages in a flow alert
      externalDocs:
        url: ''
    LabelFilters:
      title: Label filters
      type: object
      properties:
        applicationName:
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/LabelFilterType'
          description: The application name.
        severities:
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/LogSeverity'
          description: The severities.
        subsystemName:
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/LabelFilterType'
          description: The subsystem name.
      description: Filters for application name, subsystem name, and log severities
      externalDocs:
        url: ''
    LogsAnomalyConditionType:
      enum:
        - LOGS_ANOMALY_CONDITION_TYPE_MORE_THAN_USUAL_OR_UNSPECIFIED
      type: string
      description: Logs anomaly condition type.
    LogsTimeWindow:
      title: Log-based alert time window
      type: object
      properties:
        logsTimeWindowSpecificValue:
          $ref: '#/components/schemas/LogsTimeWindowValue'
      description: Time window configuration for log-based alerts
      externalDocs:
        url: ''
    LogsNewValueTimeWindow:
      title: Log-based new value alert time window
      type: object
      properties:
        logsNewValueTimeWindowSpecificValue:
          $ref: '#/components/schemas/LogsNewValueTimeWindowValue'
      description: Time window configuration for log-based new value alerts
      externalDocs:
        url: ''
    LogsRatioConditionType:
      enum:
        - LOGS_RATIO_CONDITION_TYPE_MORE_THAN_OR_UNSPECIFIED
        - LOGS_RATIO_CONDITION_TYPE_LESS_THAN
      type: string
      description: Logs ratio condition type.
    LogsRatioTimeWindow:
      title: Logs ratio time window
      type: object
      properties:
        logsRatioTimeWindowSpecificValue:
          $ref: '#/components/schemas/LogsRatioTimeWindowValue'
      description: Time window configuration for ratio alerts
      externalDocs:
        description: Learn more about log-based ratio alerts in our documentation
        url: >-
          https://coralogix.com/docs/user-guides/alerting/create-an-alert/logs/ratio-alerts/
    LogsThresholdConditionType:
      enum:
        - LOGS_THRESHOLD_CONDITION_TYPE_MORE_THAN_OR_UNSPECIFIED
        - LOGS_THRESHOLD_CONDITION_TYPE_LESS_THAN
      type: string
      description: Logs threshold condition type.
    LogsTimeRelativeComparedTo:
      enum:
        - LOGS_TIME_RELATIVE_COMPARED_TO_PREVIOUS_HOUR_OR_UNSPECIFIED
        - LOGS_TIME_RELATIVE_COMPARED_TO_SAME_HOUR_YESTERDAY
        - LOGS_TIME_RELATIVE_COMPARED_TO_SAME_HOUR_LAST_WEEK
        - LOGS_TIME_RELATIVE_COMPARED_TO_YESTERDAY
        - LOGS_TIME_RELATIVE_COMPARED_TO_SAME_DAY_LAST_WEEK
        - LOGS_TIME_RELATIVE_COMPARED_TO_SAME_DAY_LAST_MONTH
      type: string
      description: Logs time relative compared to.
    LogsTimeRelativeConditionType:
      enum:
        - LOGS_TIME_RELATIVE_CONDITION_TYPE_MORE_THAN_OR_UNSPECIFIED
        - LOGS_TIME_RELATIVE_CONDITION_TYPE_LESS_THAN
      type: string
      description: Logs time relative condition type.
    LogsUniqueValueTimeWindow:
      title: Log-based unique value alert time window
      type: object
      properties:
        logsUniqueValueTimeWindowSpecificValue:
          $ref: '#/components/schemas/LogsUniqueValueTimeWindowValue'
      description: Time window configuration for log-based unique value alerts
      externalDocs:
        url: ''
    MetricAnomalyConditionType:
      enum:
        - METRIC_ANOMALY_CONDITION_TYPE_MORE_THAN_USUAL_OR_UNSPECIFIED
        - METRIC_ANOMALY_CONDITION_TYPE_LESS_THAN_USUAL
      type: string
      description: Metric anomaly condition type.
    MetricTimeWindow:
      title: Metric time window
      type: object
      oneOf:
        - required:
            - metricTimeWindowSpecificValue
          type: object
        - required:
            - metricTimeWindowDynamicDuration
          type: object
        - type: object
          not:
            anyOf:
              - required:
                  - metricTimeWindowSpecificValue
                type: object
              - required:
                  - metricTimeWindowDynamicDuration
                type: object
      properties:
        metricTimeWindowDynamicDuration:
          minLength: 0
          type: string
          description: The time window as a dynamic value
          example: 1h30m
        metricTimeWindowSpecificValue:
          $ref: '#/components/schemas/MetricTimeWindowValue'
      description: Metric time window.
      externalDocs:
        url: ''
    MetricThresholdConditionType:
      enum:
        - METRIC_THRESHOLD_CONDITION_TYPE_MORE_THAN_OR_UNSPECIFIED
        - METRIC_THRESHOLD_CONDITION_TYPE_LESS_THAN
        - METRIC_THRESHOLD_CONDITION_TYPE_MORE_THAN_OR_EQUALS
        - METRIC_THRESHOLD_CONDITION_TYPE_LESS_THAN_OR_EQUALS
      type: string
      description: Metric threshold condition type.
    v3.SourceOverrides:
      title: Source overrides
      type: object
      properties:
        connectorConfigFields:
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/v3.ConnectorConfigField'
          description: Connector configuration fields
        messageConfigFields:
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/v3.MessageConfigField'
          description: Notification message configuration fields
        payloadType:
          minLength: 0
          type: string
          description: the payload type for the notification
          example: >-
            slack_raw, slack_structured, pagerduty_triggered,
            pagerduty_resolved, generic_https_default
      description: Source overrides.
      externalDocs:
        url: ''
    Recipients:
      title: Recipients
      type: object
      properties:
        emails:
          maxItems: 100
          minItems: 1
          type: array
          items:
            maxLength: 4096
            minLength: 1
            pattern: ^[\s\S]*$
            type: string
            description: The list of email recipients for alert notifications
          description: The list of email recipients for alert notifications
          example:
            - mail@gmail.com
      description: List of email recipients for alert notifications
      externalDocs:
        url: ''
    TimeDuration:
      title: Time duration
      type: object
      properties:
        duration:
          maxLength: 20
          minLength: 1
          pattern: ^[0-9]+$
          type: string
          description: The duration value
          example: '24'
        unit:
          $ref: '#/components/schemas/DurationUnit'
      description: Configuration for time duration
      externalDocs:
        url: ''
    SloThresholdCondition:
      title: SLO Threshold Condition
      type: object
      properties:
        threshold:
          minimum: 0
          type: number
          description: Threshold value.
          format: double
      description: Condition for the SLO threshold rule
      externalDocs:
        url: ''
    TracingLabelFilters:
      title: Tracing label filters
      type: object
      properties:
        applicationName:
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/TracingFilterType'
          description: Filter by application names
        operationName:
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/TracingFilterType'
          description: Filter by operation names
        serviceName:
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/TracingFilterType'
          description: Filter by service names
        spanFields:
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/TracingSpanFieldsFilterType'
          description: Filter by span fields
        subsystemName:
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/TracingFilterType'
          description: Filter by subsystem names
      description: >-
        Filters for application name, subsystem name, service name, operation
        name and span fields
      externalDocs:
        url: ''
    TracingThresholdConditionType:
      enum:
        - TRACING_THRESHOLD_CONDITION_TYPE_MORE_THAN_OR_UNSPECIFIED
      type: string
      description: Tracing threshold condition type.
    TracingTimeWindow:
      title: Tracing time window
      type: object
      properties:
        tracingTimeWindowValue:
          $ref: '#/components/schemas/TracingTimeWindowValue'
      description: Tracing time window.
      externalDocs:
        url: ''
    FlowStagesGroupsAlertDefs:
      title: Flow stage group alert definitions
      type: object
      properties:
        id:
          maxLength: 36
          minLength: 1
          pattern: ^[\s\S]*$
          type: string
          description: The alert definition ID
          example: 123e4567-e89b-12d3-a456-426614174000
        not:
          type: boolean
          description: Whether to negate the alert definition or not.
          example: true
      description: Alert definitions for a flow stage group
      externalDocs:
        url: ''
    AlertsOp:
      enum:
        - ALERTS_OP_AND_OR_UNSPECIFIED
        - ALERTS_OP_OR
      type: string
      description: Alerts op.
    NextOp:
      enum:
        - NEXT_OP_AND_OR_UNSPECIFIED
        - NEXT_OP_OR
      type: string
      description: Next op.
    LabelFilterType:
      title: Label filter type
      type: object
      properties:
        operation:
          $ref: '#/components/schemas/LogFilterOperationType'
        value:
          minLength: 0
          type: string
          description: The value of the label to filter by
          example: my-app
      description: Label filter type for log entries
      externalDocs:
        url: ''
    LogSeverity:
      enum:
        - LOG_SEVERITY_VERBOSE_UNSPECIFIED
        - LOG_SEVERITY_DEBUG
        - LOG_SEVERITY_INFO
        - LOG_SEVERITY_WARNING
        - LOG_SEVERITY_ERROR
        - LOG_SEVERITY_CRITICAL
      type: string
    LogsTimeWindowValue:
      enum:
        - LOGS_TIME_WINDOW_VALUE_MINUTES_5_OR_UNSPECIFIED
        - LOGS_TIME_WINDOW_VALUE_MINUTES_10
        - LOGS_TIME_WINDOW_VALUE_MINUTES_20
        - LOGS_TIME_WINDOW_VALUE_MINUTES_15
        - LOGS_TIME_WINDOW_VALUE_MINUTES_30
        - LOGS_TIME_WINDOW_VALUE_HOUR_1
        - LOGS_TIME_WINDOW_VALUE_HOURS_2
        - LOGS_TIME_WINDOW_VALUE_HOURS_4
        - LOGS_TIME_WINDOW_VALUE_HOURS_6
        - LOGS_TIME_WINDOW_VALUE_HOURS_12
        - LOGS_TIME_WINDOW_VALUE_HOURS_24
        - LOGS_TIME_WINDOW_VALUE_HOURS_36
      type: string
      description: Logs time window value.
    LogsNewValueTimeWindowValue:
      enum:
        - LOGS_NEW_VALUE_TIME_WINDOW_VALUE_HOURS_12_OR_UNSPECIFIED
        - LOGS_NEW_VALUE_TIME_WINDOW_VALUE_HOURS_24
        - LOGS_NEW_VALUE_TIME_WINDOW_VALUE_HOURS_48
        - LOGS_NEW_VALUE_TIME_WINDOW_VALUE_HOURS_72
        - LOGS_NEW_VALUE_TIME_WINDOW_VALUE_WEEK_1
        - LOGS_NEW_VALUE_TIME_WINDOW_VALUE_MONTH_1
        - LOGS_NEW_VALUE_TIME_WINDOW_VALUE_MONTHS_2
        - LOGS_NEW_VALUE_TIME_WINDOW_VALUE_MONTHS_3
      type: string
      description: Logs new value time window value.
    LogsRatioTimeWindowValue:
      enum:
        - LOGS_RATIO_TIME_WINDOW_VALUE_MINUTES_5_OR_UNSPECIFIED
        - LOGS_RATIO_TIME_WINDOW_VALUE_MINUTES_10
        - LOGS_RATIO_TIME_WINDOW_VALUE_MINUTES_15
        - LOGS_RATIO_TIME_WINDOW_VALUE_MINUTES_30
        - LOGS_RATIO_TIME_WINDOW_VALUE_HOUR_1
        - LOGS_RATIO_TIME_WINDOW_VALUE_HOURS_2
        - LOGS_RATIO_TIME_WINDOW_VALUE_HOURS_4
        - LOGS_RATIO_TIME_WINDOW_VALUE_HOURS_6
        - LOGS_RATIO_TIME_WINDOW_VALUE_HOURS_12
        - LOGS_RATIO_TIME_WINDOW_VALUE_HOURS_24
        - LOGS_RATIO_TIME_WINDOW_VALUE_HOURS_36
      type: string
      description: Logs ratio time window value.
    LogsUniqueValueTimeWindowValue:
      enum:
        - LOGS_UNIQUE_VALUE_TIME_WINDOW_VALUE_MINUTE_1_OR_UNSPECIFIED
        - LOGS_UNIQUE_VALUE_TIME_WINDOW_VALUE_MINUTES_5
        - LOGS_UNIQUE_VALUE_TIME_WINDOW_VALUE_MINUTES_10
        - LOGS_UNIQUE_VALUE_TIME_WINDOW_VALUE_MINUTES_15
        - LOGS_UNIQUE_VALUE_TIME_WINDOW_VALUE_MINUTES_20
        - LOGS_UNIQUE_VALUE_TIME_WINDOW_VALUE_MINUTES_30
        - LOGS_UNIQUE_VALUE_TIME_WINDOW_VALUE_HOURS_1
        - LOGS_UNIQUE_VALUE_TIME_WINDOW_VALUE_HOURS_2
        - LOGS_UNIQUE_VALUE_TIME_WINDOW_VALUE_HOURS_4
        - LOGS_UNIQUE_VALUE_TIME_WINDOW_VALUE_HOURS_6
        - LOGS_UNIQUE_VALUE_TIME_WINDOW_VALUE_HOURS_12
        - LOGS_UNIQUE_VALUE_TIME_WINDOW_VALUE_HOURS_24
        - LOGS_UNIQUE_VALUE_TIME_WINDOW_VALUE_HOURS_36
      type: string
      description: Logs unique value time window value.
    MetricTimeWindowValue:
      enum:
        - METRIC_TIME_WINDOW_VALUE_MINUTES_1_OR_UNSPECIFIED
        - METRIC_TIME_WINDOW_VALUE_MINUTES_5
        - METRIC_TIME_WINDOW_VALUE_MINUTES_10
        - METRIC_TIME_WINDOW_VALUE_MINUTES_15
        - METRIC_TIME_WINDOW_VALUE_MINUTES_20
        - METRIC_TIME_WINDOW_VALUE_MINUTES_30
        - METRIC_TIME_WINDOW_VALUE_HOUR_1
        - METRIC_TIME_WINDOW_VALUE_HOURS_2
        - METRIC_TIME_WINDOW_VALUE_HOURS_4
        - METRIC_TIME_WINDOW_VALUE_HOURS_6
        - METRIC_TIME_WINDOW_VALUE_HOURS_12
        - METRIC_TIME_WINDOW_VALUE_HOURS_24
        - METRIC_TIME_WINDOW_VALUE_HOURS_36
      type: string
      description: Metric time window value.
    v3.ConnectorConfigField:
      title: Connector config field
      type: object
      properties:
        fieldName:
          minLength: 0
          type: string
          description: The name of the configuration field
          example: description
        template:
          minLength: 0
          type: string
          description: The template for the configuration field
          example: template_example
      externalDocs:
        url: ''
    v3.MessageConfigField:
      title: Message config field
      type: object
      properties:
        fieldName:
          minLength: 0
          type: string
          description: The name of the configuration field
          example: description
        template:
          minLength: 0
          type: string
          description: The template for the configuration field
          example: template_example
      description: Configuration field for a notification message
      externalDocs:
        url: ''
    DurationUnit:
      enum:
        - DURATION_UNIT_UNSPECIFIED
        - DURATION_UNIT_HOURS
      type: string
      description: Duration unit.
    TracingFilterType:
      title: Tracing filter type
      type: object
      properties:
        operation:
          $ref: '#/components/schemas/TracingFilterOperationType'
        values:
          minItems: 1
          type: array
          items:
            minLength: 0
            type: string
            description: The values of the label to filter by
          description: The values of the label to filter by
          example:
            - value1
            - value2
      description: Filter type for trace entries
      externalDocs:
        url: ''
    TracingSpanFieldsFilterType:
      title: Tracing span fields filter type
      type: object
      properties:
        filterType:
          $ref: '#/components/schemas/TracingFilterType'
        key:
          minLength: 0
          type: string
          description: The key of the span field to filter by
          example: span.field.key
      description: A filter for span fields in trace entries
      externalDocs:
        url: ''
    TracingTimeWindowValue:
      enum:
        - TRACING_TIME_WINDOW_VALUE_MINUTES_5_OR_UNSPECIFIED
        - TRACING_TIME_WINDOW_VALUE_MINUTES_10
        - TRACING_TIME_WINDOW_VALUE_MINUTES_15
        - TRACING_TIME_WINDOW_VALUE_MINUTES_20
        - TRACING_TIME_WINDOW_VALUE_MINUTES_30
        - TRACING_TIME_WINDOW_VALUE_HOUR_1
        - TRACING_TIME_WINDOW_VALUE_HOURS_2
        - TRACING_TIME_WINDOW_VALUE_HOURS_4
        - TRACING_TIME_WINDOW_VALUE_HOURS_6
        - TRACING_TIME_WINDOW_VALUE_HOURS_12
        - TRACING_TIME_WINDOW_VALUE_HOURS_24
        - TRACING_TIME_WINDOW_VALUE_HOURS_36
      type: string
      description: Tracing time window value.
    LogFilterOperationType:
      enum:
        - LOG_FILTER_OPERATION_TYPE_IS_OR_UNSPECIFIED
        - LOG_FILTER_OPERATION_TYPE_INCLUDES
        - LOG_FILTER_OPERATION_TYPE_ENDS_WITH
        - LOG_FILTER_OPERATION_TYPE_STARTS_WITH
      type: string
      description: Log filter operation type.
    TracingFilterOperationType:
      enum:
        - TRACING_FILTER_OPERATION_TYPE_IS_OR_UNSPECIFIED
        - TRACING_FILTER_OPERATION_TYPE_INCLUDES
        - TRACING_FILTER_OPERATION_TYPE_ENDS_WITH
        - TRACING_FILTER_OPERATION_TYPE_STARTS_WITH
        - TRACING_FILTER_OPERATION_TYPE_IS_NOT
      type: string
      description: Tracing filter operation type.
  securitySchemes:
    apiKeyAuth:
      type: apiKey
      in: header
      name: Authorization
      description: API key authentication

````