> ## Documentation Index
> Fetch the complete documentation index at: https://docs.coralogix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List cases with filters

> List cases using filters, pagination and custom ordering.

Requires the following permissions:
- `case:Read`



## OpenAPI

````yaml openapi_v5.yaml post /cases/cases/v1
openapi: 3.0.0
info:
  title: ''
  version: 1.0.0
servers:
  - url: https://api.coralogix.com/mgmt/openapi/5
  - url: https://api.eu2.coralogix.com/mgmt/openapi/5
  - url: https://api.coralogix.us/mgmt/openapi/5
  - url: https://api.cx498.coralogix.com/mgmt/openapi/5
  - url: https://api.coralogix.in/mgmt/openapi/5
  - url: https://api.coralogixsg.com/mgmt/openapi/5
  - url: https://api.ap3.coralogix.com/mgmt/openapi/5
security:
  - apiKeyAuth: []
tags:
  - name: AI Applications Service
    description: Manage the catalog of AI applications discovered from spans.
    externalDocs:
      url: ''
  - name: AI Evaluations Service
    description: >-
      Manage AI evaluations and the custom evaluation catalog for AI
      applications.
    externalDocs:
      url: ''
  - name: API Keys Admin Service
    description: Administrative operations for API Keys management.
    externalDocs:
      url: ''
  - name: API Keys Service
    description: Manage your API Keys.
    externalDocs:
      url: ''
  - name: Actions Service
    description: View and manage your Actions.
    externalDocs:
      url: ''
  - name: Alert Scheduler Rule service
    description: Manage your alert scheduler rules.
    externalDocs:
      url: ''
  - name: Alert definitions service
    description: >-
      View and manage your alerts using alert definitions - data structures that
      contain the configuration required to create an alert.
    externalDocs:
      description: Learn more about alerts in our documentation
      url: https://coralogix.com/docs/user-guides/alerting/introduction-to-alerts/
  - name: Alert events service
    description: >-
      Get information regarding your alert events - instances of alerts being
      triggered.
    externalDocs:
      description: Learn more about alert events and incidents in our documentation.
      url: https://coralogix.com/docs/user-guides/alerting/incidents/
  - name: Case Events service
    description: Manage case events, comments, and external thread synchronization.
    externalDocs:
      url: ''
  - name: Case Settings service
    description: Manage case settings team configurations.
    externalDocs:
      url: ''
  - name: Cases notification service
    description: Track notification adjacent data for cases.
    externalDocs:
      url: ''
  - name: Cases service
    description: >-
      Manage cases throughout their lifecycle. Create, view, assign,
      acknowledge, unacknowledge, resolve, and close cases to streamline
      investigations and follow-ups.
    externalDocs:
      description: Learn more about Cases in our documentation
      url: https://coralogix.com/docs/user-guides/cases/
  - name: Connector Schema service
    description: Retrieve connector schemas for notification center integrations
    externalDocs:
      description: Learn more about connectors in our documentation
      url: >-
        https://coralogix.com/docs/user-guides/notification-center/connectors/introduction/
  - name: Connectors service
    description: >-
      View and manage your connectors - integration instances for notification
      destinations
    externalDocs:
      description: Lean more about connectors in our documentation
      url: >-
        https://coralogix.com/docs/user-guides/notification-center/connectors/introduction/
  - name: Contextual data integration service
    description: Query for contextual data integration information.
    externalDocs:
      url: ''
  - name: Custom Enrichments Service
    description: Manage your enrichments.
    externalDocs:
      url: ''
  - name: Dashboard folders service
    description: Manage your dashboard folders.
    externalDocs:
      url: ''
  - name: Dashboard service
    description: Get information about the Coralogix Dashboard catalog.
    externalDocs:
      url: ''
  - name: Data Usage Query service
    description: >-
      Query billable data usage through the public Coralogix API using daily or
      hourly bucketed aggregations over supported labels.
    externalDocs:
      url: ''
  - name: Data Usage Service
    description: A service to manage data usage metrics.
    externalDocs:
      url: ''
  - name: Enrichments Service
    description: Manage your enrichments.
    externalDocs:
      url: ''
  - name: Entities service
    description: Query information about registered entities in the notification center
    externalDocs:
      description: Lean more about the notification center in our documentation
      url: https://coralogix.com/docs/user-guides/notification-center/introduction/
  - name: Events Service
    description: A service for querying events.
    externalDocs:
      description: Learn more about alerts in our documentation
      url: https://coralogix.com/docs/user-guides/alerting/introduction-to-alerts/
  - name: Events2Metrics Service
    description: Manage your events2metrics.
    externalDocs:
      url: ''
  - name: Extension deployment service
    description: A service that enables querying for extension deployment information.
    externalDocs:
      description: Find out more about extensions in our documentation.
      url: https://coralogix.com/docs/integrations/extensions/
  - name: Extension service
    description: A service that enables querying for extension information.
    externalDocs:
      description: Learn more about extensions in our documentation.
      url: https://coralogix.com/docs/integrations/extensions/
  - name: Folders for views service
    description: Create and manage view folders.
    externalDocs:
      url: ''
  - name: Global routers service
    description: >-
      View and manage your global routers - entities that direct notifications
      to configured destinations based on conditions
    externalDocs:
      description: Lean more about global routers in our documentation
      url: >-
        https://coralogix.com/docs/user-guides/notification-center/routing/introduction/
  - name: IP access service
    description: >-
      IP access service provides the API for managing company IP access
      settings.
    externalDocs:
      url: ''
  - name: Incidents service
    description: >-
      Handle all operations related to incident management within Coralogix.
      Identify, manage, and resolve incidents efficiently through automated
      workflows and team collaboration.
    externalDocs:
      description: Find out more about incident management in our documentation
      url: https://coralogix.com/docs/user-guides/alerting/incidents/
  - name: Integration service
    description: A service that enables querying for integration information.
    externalDocs:
      description: Find out more about integrations in our documentation.
      url: https://coralogix.com/docs/integrations/getting-started/
  - name: Metrics Data Archive Service
    description: View and manage your storage targets for metrics.
    externalDocs:
      description: Find out more about archives
      url: >-
        https://coralogix.com/docs/user-guides/data-flow/s3-archive/connect-s3-archive/
  - name: Notifications testing service
    description: >-
      Test your notification center configurations including connectors,
      presets, and templates
    externalDocs:
      description: Lean more about the notification center in our documentation
      url: https://coralogix.com/docs/user-guides/notification-center/introduction/
  - name: Outgoing webhooks service
    externalDocs:
      description: Find out more about outbound webhooks in our documentation.
      url: >-
        https://coralogix.com/docs/user-guides/alerting/outbound-webhooks/generic-outbound-webhooks-alert-webhooks/
  - name: Policies Service
    description: View and manage your TCO policies
    externalDocs:
      url: ''
  - name: Presets service
    description: >-
      View and manage your presets - pre-configured templates for notification
      content rendering
    externalDocs:
      description: Lean more about presets in our documentation
      url: >-
        https://coralogix.com/docs/user-guides/notification-center/presets/introduction/
  - name: Quota Allocation Rule Set service
    description: Manage quota allocation rules for different entity types.
    externalDocs:
      url: ''
  - name: Recording Rules Service
    description: A service to manage recording rules.
    externalDocs:
      url: ''
  - name: Retentions Service
    description: View and manage retentions
    externalDocs:
      url: ''
  - name: Role Management Service
    description: Service for managing system and custom roles.
    externalDocs:
      url: ''
  - name: Rule Groups Service
    description: A service to manage rule groups.
    externalDocs:
      url: ''
  - name: SAML Configuration Service
    description: Manage your SAML configuration
    externalDocs:
      url: ''
  - name: Scopes Service
    description: A service to manage scopes
    externalDocs:
      url: ''
  - name: Slos Service
    description: A service for managing Service Level Objectives (SLOs).
    externalDocs:
      url: ''
  - name: Target Service
    description: View and manage your storage targets for logs.
    externalDocs:
      description: Find out more about archives
      url: >-
        https://coralogix.com/docs/user-guides/data-flow/s3-archive/connect-s3-archive/
  - name: Team Groups Management Service
    description: Manage Team Groups.
    externalDocs:
      url: ''
  - name: Users Management Service
    description: >-
      Manage team members (users) including creation, updates, search, and
      status management.
    externalDocs:
      url: ''
  - name: Views service
    description: Create and manage views.
    externalDocs:
      url: ''
paths:
  /cases/cases/v1:
    post:
      tags:
        - Cases service
      summary: List cases with filters
      description: |-
        List cases using filters, pagination and custom ordering.

        Requires the following permissions:
        - `case:Read`
      operationId: CasesService_ListCases
      requestBody:
        content:
          application/json:
            schema:
              description: Request to list cases with filtering and pagination
              properties:
                filters:
                  $ref: '#/components/schemas/CaseFilters'
                orderBy:
                  $ref: '#/components/schemas/CaseOrderBy'
                pagination:
                  $ref: '#/components/schemas/cases.v1.PaginationRequest'
              title: List cases request
              type: object
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListCasesResponse'
          description: ''
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
          description: Bad Request
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
          description: Unauthorized request
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
          description: Internal server error
      externalDocs:
        url: ''
components:
  schemas:
    CaseFilters:
      title: Case filters
      type: object
      properties:
        alertFilters:
          $ref: '#/components/schemas/AlertFilters'
        assignees:
          maxItems: 1000
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/AssigneeOption'
          description: List of case assignees to filter on
        breached:
          maxItems: 1000
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/KPIFilter'
          description: >-
            KPI-based filters applied to cases. When absent, KPI filter is not
            applied at all.
          example:
            - KPI_FILTER_NOT_BREACHED
        caseLabelsFilter:
          $ref: '#/components/schemas/CaseLabelsFilter'
        categories:
          maxItems: 1000
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/CaseCategory'
          description: List of case categories to filter on
          example:
            - CASE_CATEGORY_SECURITY
            - CASE_CATEGORY_AVAILABILITY
        connectorTypeFilters:
          maxItems: 1000
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/ConnectorTypeFilter'
          description: >-
            Connector type filters applied to cases, including cases with no
            connector linked.
        dateRange:
          $ref: '#/components/schemas/DateRangeFilter'
        groupings:
          maxItems: 1000
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/FilterGroup'
          description: Grouping-based filters (e.g., service, subsystem)
        indicatorTypes:
          maxItems: 1000
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/IndicatorType'
          description: List of indicator types to filter on
        labels:
          maxItems: 1000
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/FilterGroup'
          description: Label-based filters applied to cases
        priorities:
          maxItems: 1000
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/CasePriority'
          description: List of case priorities to filter on
          example:
            - CASE_PRIORITY_P1
            - CASE_PRIORITY_P2
        statuses:
          maxItems: 1000
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/CaseStatus'
          description: List of case statuses to filter on
        textSearch:
          maxLength: 4096
          minLength: 1
          pattern: ^[\s\S]*$
          type: string
          description: Test search query applied to case titles
          example: Vulnerability
      description: >-
        Filters applied when querying cases, including statuses, priorities,
        categories, groupings, and labels.
      externalDocs:
        url: ''
    CaseOrderBy:
      title: Case ordering specification
      type: object
      properties:
        direction:
          $ref: '#/components/schemas/CaseOrderByDirection'
        field:
          $ref: '#/components/schemas/CaseOrderByField'
      description: >-
        Defines how cases should be sorted in the response. By default, cases
        are sorted by creation time and id in descending order. With this field,
        one can specify the primary sorting field and direction.
      externalDocs:
        url: ''
    cases.v1.PaginationRequest:
      title: Pagination request
      type: object
      properties:
        pageSize:
          maximum: 1000
          minimum: 1
          type: integer
          description: Number of items to return per page
          format: int64
          example: 10
        pageToken:
          maxLength: 4096
          minLength: 1
          pattern: ^[\s\S]*$
          type: string
          description: Token for the next page of results
          example: >-
            MjAyNS0wOS0yM1QxMjoxMTo0MC43ODcwODVaLDY5YmIxYmFiLWE1NzAtNGU5Ny04MzE2LWFkYzQxYjk2Y2QyNA==
        skip:
          maximum: 1000000
          minimum: 0
          type: integer
          description: Number of items to skip before starting to collect results
          format: int64
          example: 20
      description: Pagination parameters for list requests.
      externalDocs:
        url: ''
    ListCasesResponse:
      title: List cases response
      required:
        - cases
        - pagination
      type: object
      properties:
        cases:
          maxItems: 1000
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/Case'
          description: Cases matching the provided filters.
        pagination:
          $ref: '#/components/schemas/cases.v1.PaginationResponse'
      description: Response containing a list of cases and pagination information
      externalDocs:
        url: ''
    Error:
      type: object
      properties:
        code:
          maximum: 599
          minimum: 100
          type: integer
          description: HTTP status code of the error (for example 400, 404, 500).
          format: int32
        message:
          maxLength: 4096
          minLength: 0
          pattern: ^[\s\S]*$
          type: string
          description: Human-readable description of the error.
      description: Standard error response body returned for a failed request.
    AlertFilters:
      title: Alert filters
      type: object
      properties:
        alertIds:
          maxItems: 1000
          minItems: 0
          type: array
          items:
            maxLength: 36
            minLength: 36
            pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
            type: string
            description: >-
              List of alert IDs to filter on. Cases containing any of these
              alert IDs will be returned (OR logic).
          description: >-
            List of alert IDs to filter on. Cases containing any of these alert
            IDs will be returned (OR logic).
          example:
            - f56645c5-9cd4-4b9f-961f-4f852d8835a0
            - a0a08c31-0ae4-4600-928e-cb6b7da50a99
        alertVersions:
          maxItems: 1000
          minItems: 0
          type: array
          items:
            maxLength: 64
            minLength: 1
            pattern: ^[\s\S]*$
            type: string
            description: >-
              List of alert version IDs to filter on. Cases containing
              indicators with any of these alert version IDs will be returned
              (OR logic).
          description: >-
            List of alert version IDs to filter on. Cases containing indicators
            with any of these alert version IDs will be returned (OR logic).
          example:
            - 550e8400-e29b-41d4-a716-446655440000
            - 6ba7b810-9dad-11d1-80b4-00c04fd430c8
      description: Filters applied to cases based on alert properties.
      externalDocs:
        url: ''
    AssigneeOption:
      title: Assignee option
      type: object
      oneOf:
        - required:
            - assignee
          type: object
        - required:
            - unassigned
          type: object
        - type: object
          not:
            anyOf:
              - required:
                  - assignee
                type: object
              - required:
                  - unassigned
                type: object
      properties:
        assignee:
          maxLength: 256
          minLength: 1
          pattern: ^[\s\S]*$
          type: string
          description: User identifier of the assignee to filter by
          example: e07db42e-eb1c-4c14-ab68-e4d245ae63a5
        unassigned:
          $ref: '#/components/schemas/Unassigned'
      description: >-
        Assignee filter option representing either a specific assignee or
        unassigned cases.
      externalDocs:
        url: ''
    KPIFilter:
      enum:
        - KPI_FILTER_UNSPECIFIED
        - KPI_FILTER_TIME_TO_ACKNOWLEDGE_BREACHED
        - KPI_FILTER_TIME_TO_RESOLVE_BREACHED
        - KPI_FILTER_NOT_BREACHED
        - KPI_FILTER_TIME_TO_UPDATE_BREACHED
      type: string
    CaseLabelsFilter:
      title: Case Labels Filter
      type: object
      properties:
        flatLabels:
          maxItems: 1000
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/v1.KeyValue'
          description: List of case key:value labels to filter on
      description: Filters applied against Case's labels when queries/filters counted
      externalDocs:
        url: ''
    CaseCategory:
      title: Case category
      enum:
        - CASE_CATEGORY_UNSPECIFIED
        - CASE_CATEGORY_SECURITY
        - CASE_CATEGORY_AVAILABILITY
      type: string
      description: Broad category of the case (e.g., security, availability).
    ConnectorTypeFilter:
      title: Connector type filters
      type: object
      oneOf:
        - required:
            - connectorType
          type: object
        - required:
            - noConnector
          type: object
        - type: object
          not:
            anyOf:
              - required:
                  - connectorType
                type: object
              - required:
                  - noConnector
                type: object
      properties:
        connectorType:
          $ref: '#/components/schemas/v1.ConnectorType'
        noConnector:
          $ref: '#/components/schemas/NoConnector'
      description: Filters applied to cases based on connector types.
      externalDocs:
        url: ''
    DateRangeFilter:
      title: Date Range Filter
      required:
        - from
        - to
      type: object
      properties:
        from:
          maxLength: 30
          minLength: 20
          type: string
          description: Timestamp marking the start of the date range
          format: date-time
          example: '2025-09-22T10:30:00.000Z'
        mode:
          $ref: '#/components/schemas/DateRangeMode'
        to:
          maxLength: 30
          minLength: 20
          type: string
          description: Timestamp marking the end of the date range
          format: date-time
          example: '2025-09-22T10:30:00.000Z'
      description: A filter defining a date range with 'from' and 'to' timestamps.
      externalDocs:
        url: ''
    FilterGroup:
      title: Filter group
      required:
        - key
        - values
      type: object
      properties:
        key:
          maxLength: 4096
          minLength: 1
          pattern: ^[\s\S]*$
          type: string
          description: Key of the filter group (e.g., service, environment)
          example: service
        values:
          maxItems: 1000
          minItems: 0
          type: array
          items:
            maxLength: 4096
            minLength: 1
            pattern: ^[\s\S]*$
            type: string
            description: Values associated with the filter group key
          description: Values associated with the filter group key
          example:
            - payments
      description: A filter group containing a key and its possible values.
      externalDocs:
        url: ''
    IndicatorType:
      enum:
        - INDICATOR_TYPE_UNSPECIFIED
        - INDICATOR_TYPE_ALERT
        - INDICATOR_TYPE_PROMETHEUS_ALERTMANAGER
        - INDICATOR_TYPE_ERROR_TRACKING
      type: string
    CasePriority:
      enum:
        - CASE_PRIORITY_UNSPECIFIED
        - CASE_PRIORITY_P1
        - CASE_PRIORITY_P2
        - CASE_PRIORITY_P3
        - CASE_PRIORITY_P4
        - CASE_PRIORITY_P5
      type: string
      description: Case priority.
    CaseStatus:
      enum:
        - CASE_STATUS_UNSPECIFIED
        - CASE_STATUS_PENDING_ACTIVATION
        - CASE_STATUS_ACTIVE
        - CASE_STATUS_ACKNOWLEDGED
        - CASE_STATUS_RESOLVED
        - CASE_STATUS_CLOSED
      type: string
      description: Case status.
    CaseOrderByDirection:
      title: Case order direction
      enum:
        - CASE_ORDER_BY_DIRECTION_UNSPECIFIED
        - CASE_ORDER_BY_DIRECTION_ASCENDING
        - CASE_ORDER_BY_DIRECTION_DESCENDING
      type: string
      description: Direction in which cases are sorted (ascending or descending).
    CaseOrderByField:
      title: Case order field
      enum:
        - CASE_ORDER_BY_FIELD_UNSPECIFIED
        - CASE_ORDER_BY_FIELD_PRIORITY
        - CASE_ORDER_BY_FIELD_STATUS
        - CASE_ORDER_BY_FIELD_UPDATED_AT
        - CASE_ORDER_BY_FIELD_CATEGORY
        - CASE_ORDER_BY_FIELD_DURATION
        - CASE_ORDER_BY_FIELD_CREATED_AT
      type: string
      description: Field used for ordering cases (e.g., priority, status, category).
    Case:
      title: Case
      required:
        - id
        - title
        - status
        - priority
        - category
        - createTime
        - labels
        - groupings
        - impactedEntities
      type: object
      properties:
        acknowledgeTime:
          maxLength: 30
          minLength: 20
          type: string
          description: When the case was acknowledged
          format: date-time
        aiSummary:
          maxLength: 4096
          minLength: 1
          pattern: ^[\s\S]*$
          type: string
          description: AI summary of the case
        assignee:
          $ref: '#/components/schemas/cases.v1.UserDetails'
        caseIndicators:
          $ref: '#/components/schemas/CaseIndicators'
        category:
          $ref: '#/components/schemas/CaseCategory'
        createTime:
          maxLength: 30
          minLength: 20
          type: string
          description: When the case was created
          format: date-time
          example: '2025-09-22T10:30:00.000Z'
        duration:
          maxLength: 20
          minLength: 1
          pattern: ^[0-9]+$
          type: string
          description: Measures how long the Case is/was opened in milliseconds
        groupings:
          maxItems: 1000
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/v1.KeyValue'
          description: Grouping dimensions (e.g., service, subsystem)
        id:
          maxLength: 36
          minLength: 36
          pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
          type: string
          description: Unique identifier of the case
          example: 3f166e9f-3c88-4af2-b52e-138f339dab3e
        impactedEntities:
          maxItems: 1000
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/ImpactedEntity'
          description: Impacted entities (e.g., service, database)
        kpiBreaches:
          $ref: '#/components/schemas/KPIBreaches'
        labels:
          maxItems: 1000
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/v1.KeyValue'
          description: User-defined labels for the case
        ollyAnalysis:
          $ref: '#/components/schemas/OllyAnalysis'
        priority:
          $ref: '#/components/schemas/CasePriority'
        priorityDetails:
          $ref: '#/components/schemas/PriorityDetails'
        readableId:
          maxLength: 64
          minLength: 1
          pattern: ^[A-Z]+-[0-9]+$
          type: string
          description: >-
            Readable identifier of the case, available only for the cases that
            became Active. May be used interchangeably with `id` when calling
            Cases APIs that target a specific case.
          example: CASE-123
        resolutionDetails:
          $ref: '#/components/schemas/ResolutionDetails'
        status:
          $ref: '#/components/schemas/CaseStatus'
        title:
          maxLength: 4096
          minLength: 1
          pattern: ^[\s\S]*$
          type: string
          description: Case title
          example: Database outage investigation
        updateTime:
          maxLength: 30
          minLength: 20
          type: string
          description: When the case was last updated
          format: date-time
      description: Represents a case within the Cases service.
      externalDocs:
        url: ''
    cases.v1.PaginationResponse:
      title: Pagination response
      type: object
      properties:
        nextPageToken:
          maxLength: 4096
          minLength: 1
          pattern: ^[\s\S]*$
          type: string
          description: Token for the next page of results
          example: >-
            MjAyNS0wOS0yM1QxMjoxMTo0MC43ODcwODVaLDY5YmIxYmFiLWE1NzAtNGU5Ny04MzE2LWFkYzQxYjk2Y2QyNA==
      description: Pagination information for list responses.
      externalDocs:
        url: ''
    Unassigned:
      title: Unassigned
      type: object
      additionalProperties: false
      description: Marker selecting cases that have no assignee.
      externalDocs:
        url: ''
    v1.KeyValue:
      title: Key-value pair
      required:
        - key
        - value
      type: object
      properties:
        key:
          minLength: 0
          type: string
          description: Key of the pair (e.g., label or grouping name)
          example: service
        value:
          minLength: 0
          type: string
          description: Value associated with the key
          example: payments
      description: >-
        Represents a simple key-value pair, often used for labels or groupings
        in cases.
      externalDocs:
        url: ''
    v1.ConnectorType:
      enum:
        - CONNECTOR_TYPE_UNSPECIFIED
        - CONNECTOR_TYPE_SLACK
        - CONNECTOR_TYPE_SERVICE_NOW
        - CONNECTOR_TYPE_PAGER_DUTY
        - CONNECTOR_TYPE_EMAIL
        - CONNECTOR_TYPE_GENERIC_HTTPS
        - CONNECTOR_TYPE_MICROSOFT_TEAMS
      type: string
      description: Connector type.
    NoConnector:
      type: object
      additionalProperties: false
      description: No connector.
      externalDocs:
        url: ''
    DateRangeMode:
      title: Date range mode
      enum:
        - DATE_RANGE_MODE_UNSPECIFIED
        - DATE_RANGE_MODE_ACTIVE_WINDOW
        - DATE_RANGE_MODE_CREATED_AT
      type: string
      description: >-
        Determines how the date range is applied to cases (active window vs
        creation time).
    cases.v1.UserDetails:
      title: User details
      type: object
      properties:
        userId:
          maxLength: 36
          minLength: 36
          pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
          type: string
          description: Unique user identifier
          example: 3af152ee-9eaf-4803-87f1-23c5fb2fbaa0
      description: Minimal user identity information used in case assignments.
      externalDocs:
        url: ''
    CaseIndicators:
      title: Case indicators
      required:
        - alertIndicators
      type: object
      properties:
        alertIndicators:
          maxItems: 1000
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/AlertIndicator'
          description: List of alert indicators contributing to the case
        genericIndicators:
          maxItems: 1000
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/GenericIndicator'
          description: List of generic indicators contributing to the case
        prometheusAlertIndicators:
          maxItems: 1000
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/PrometheusAlertIndicator'
          description: List of Prometheus alert indicators contributing to the case
      description: Grouped indicators contributing to the case.
      externalDocs:
        url: ''
    ImpactedEntity:
      title: Impacted entity
      type: object
      oneOf:
        - required:
            - apmService
          type: object
        - required:
            - apmDatabase
          type: object
        - type: object
          not:
            anyOf:
              - required:
                  - apmService
                type: object
              - required:
                  - apmDatabase
                type: object
      properties:
        apmDatabase:
          $ref: '#/components/schemas/ApmDatabaseEntity'
        apmService:
          $ref: '#/components/schemas/ApmServiceEntity'
      description: Entity affected by a case (e.g., an APM service or database).
      externalDocs:
        url: ''
    KPIBreaches:
      title: KPI breaches
      required:
        - breachedKpis
      type: object
      properties:
        breachedKpis:
          maxItems: 1000
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/BreachedKPI'
          description: List of breached KPIs for the case
      description: >-
        Current or final KPI breach timestamps for the case. A value is present
        only when the KPI has been breached.
      externalDocs:
        url: ''
    OllyAnalysis:
      title: Olly analysis
      type: object
      properties:
        completedAt:
          maxLength: 30
          minLength: 20
          type: string
          description: When the analysis attempt completed.
          format: date-time
          example: '2025-09-22T10:30:00.000Z'
        payload:
          $ref: '#/components/schemas/OllyAnalysisPayload'
        status:
          $ref: '#/components/schemas/OllyAnalysisStatus'
      description: Result of an automated Olly analysis attached to a case.
      externalDocs:
        url: ''
    PriorityDetails:
      title: Priority details
      type: object
      properties:
        override:
          $ref: '#/components/schemas/CasePriority'
        system:
          $ref: '#/components/schemas/CasePriority'
      description: Priority details, including system computed and user override values.
      externalDocs:
        url: ''
    ResolutionDetails:
      title: Resolution details
      type: object
      properties:
        reason:
          maxLength: 4096
          minLength: 1
          pattern: ^[\s\S]*$
          type: string
          description: Resolution reason
          example: Case was not applicable.
        resolveTime:
          maxLength: 30
          minLength: 20
          type: string
          description: Timestamp when the case was resolved
          format: date-time
          example: '2025-09-22T11:15:00.000Z'
        resolvedBy:
          $ref: '#/components/schemas/CaseResolver'
      description: Information about how and when a case was resolved.
      externalDocs:
        url: ''
    AlertIndicator:
      title: Alert indicator
      required:
        - alertId
        - latestAlertVersion
        - priority
        - groupingType
        - state
        - triggerTime
        - alertVersions
        - permutations
      type: object
      properties:
        alertId:
          maxLength: 36
          minLength: 36
          pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
          type: string
          description: The unique alert ID (stable across versions).
          example: f56645c5-9cd4-4b9f-961f-4f852d8835a0
        alertVersions:
          maxItems: 1000
          minItems: 0
          type: array
          items:
            maxLength: 64
            minLength: 1
            pattern: ^[\s\S]*$
            type: string
            description: >-
              Array of all alert version IDs for this indicator in the case.
              Includes the latest_alert_version.
          description: >-
            Array of all alert version IDs for this indicator in the case.
            Includes the latest_alert_version.
          example:
            - 1eae3615-79e7-4b54-88e0-6a77def653bf
            - 2fbf4726-8af8-5c65-99f1-7b88ef764c0g
        groupingType:
          $ref: '#/components/schemas/AlertGroupingType'
        latestAlertVersion:
          maxLength: 64
          minLength: 1
          pattern: ^[\s\S]*$
          type: string
          description: Last seen version ID of the triggered alert definition.
          example: 1eae3615-79e7-4b54-88e0-6a77def653bf
        permutations:
          maxItems: 1000
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/AlertIndicator.Permutation'
          description: Array of the alert permutations.
        priority:
          $ref: '#/components/schemas/IndicatorPriority'
        resolveTime:
          maxLength: 30
          minLength: 20
          type: string
          description: When present, timestamp when the alert resolved.
          format: date-time
          example: '2025-09-22T11:05:00.000Z'
        state:
          $ref: '#/components/schemas/IndicatorState'
        suppression:
          $ref: '#/components/schemas/AlertSuppression'
        triggerTime:
          maxLength: 30
          minLength: 20
          type: string
          description: Timestamp when the alert triggered.
          format: date-time
          example: '2025-09-22T10:30:00.000Z'
      description: >-
        Data describing a triggered alert instance and its lifecycle relative to
        a case.
      externalDocs:
        url: ''
    GenericIndicator:
      title: Generic indicator
      required:
        - id
        - externalId
        - indicatorType
        - status
        - priority
        - lastTriggeredAt
      type: object
      properties:
        entityLinks:
          maxItems: 100
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/EntityLink'
          description: URLs to the originating entities in the external system.
        externalId:
          maxLength: 256
          minLength: 1
          pattern: ^[\s\S]*$
          type: string
          description: Opaque reference to the originating entity in the external system.
          example: et-issue-8827
        id:
          maxLength: 36
          minLength: 36
          pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
          type: string
          description: Unique identifier of this generic indicator.
          example: f56645c5-9cd4-4b9f-961f-4f852d8835a0
        indicatorType:
          $ref: '#/components/schemas/GenericIndicatorType'
        labels:
          maxItems: 1000
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/v1.KeyValue'
          description: Arbitrary key-value metadata from the originating system.
        lastResolvedAt:
          maxLength: 30
          minLength: 20
          type: string
          description: When present, timestamp when the indicator last resolved.
          format: date-time
          example: '2025-09-22T11:05:00.000Z'
        lastTriggeredAt:
          maxLength: 30
          minLength: 20
          type: string
          description: Timestamp when the indicator last triggered.
          format: date-time
          example: '2025-09-22T10:30:00.000Z'
        priority:
          $ref: '#/components/schemas/IndicatorPriority'
        status:
          $ref: '#/components/schemas/GenericIndicatorStatus'
      description: >-
        An indicator sourced from a generic external system (e.g. Error
        Tracking).
      externalDocs:
        url: ''
    PrometheusAlertIndicator:
      title: Prometheus alert indicator
      required:
        - alertGroupId
        - status
        - priority
        - groupLabels
        - receiver
        - externalUrl
        - receivedAt
        - updatedAt
        - alerts
      type: object
      properties:
        alertGroupId:
          maxLength: 256
          minLength: 1
          pattern: ^[\s\S]*$
          type: string
          description: Identifier of the Prometheus alerts group.
          example: 5d41402abc4b2a76b9719d911017c592
        alerts:
          maxItems: 1000
          minItems: 0
          type: array
          items:
            $ref: '#/components/schemas/PrometheusAlert'
          description: Individual alerts contained in this group.
        externalUrl:
          maxLength: 4096
          minLength: 1
          pattern: ^[\s\S]*$
          type: string
          description: External URL of the Alertmanager instance that emitted the group.
          example: https://alertmanager.example.com
        groupLabels:
          type: object
          additionalProperties:
            minLength: 0
            type: string
          description: Labels used to group the alerts.
        priority:
          $ref: '#/components/schemas/IndicatorPriority'
        receivedAt:
          maxLength: 30
          minLength: 20
          type: string
          description: Timestamp when the alert group was first received.
          format: date-time
          example: '2025-09-22T10:30:00.000Z'
        receiver:
          maxLength: 256
          minLength: 1
          pattern: ^[\s\S]*$
          type: string
          description: Name of the Alertmanager receiver that handled the group.
          example: webhook-coralogix
        status:
          $ref: '#/components/schemas/PrometheusAlertStatus'
        updatedAt:
          maxLength: 30
          minLength: 20
          type: string
          description: Timestamp when the alert group was last updated.
          format: date-time
          example: '2025-09-22T11:05:00.000Z'
      description: >-
        Data describing a triggered Prometheus alert group and its constituent
        alerts.
      externalDocs:
        url: ''
    ApmDatabaseEntity:
      title: APM database entity
      type: object
      properties:
        name:
          maxLength: 4096
          minLength: 1
          pattern: ^[\s\S]*$
          type: string
          description: Name of the impacted database
          example: orders-db
        system:
          maxLength: 4096
          minLength: 1
          pattern: ^[\s\S]*$
          type: string
          description: Database system (e.g., postgresql, mysql)
          example: postgresql
      description: >-
        Application Performance Monitoring database identified as impacted by a
        case.
      externalDocs:
        url: ''
    ApmServiceEntity:
      title: APM service entity
      type: object
      properties:
        language:
          maxLength: 4096
          minLength: 1
          pattern: ^[\s\S]*$
          type: string
          description: Programming language of the APM service
          example: go
        name:
          maxLength: 4096
          minLength: 1
          pattern: ^[\s\S]*$
          type: string
          description: Name of the impacted APM service
          example: payments-api
      description: >-
        Application Performance Monitoring service identified as impacted by a
        case.
      externalDocs:
        url: ''
    BreachedKPI:
      title: Breached KPI
      required:
        - id
        - createdAt
        - kpiType
        - casePriority
        - breachedAt
        - breachStatus
      type: object
      properties:
        breachStatus:
          $ref: '#/components/schemas/BreachStatus'
        breachedAt:
          maxLength: 30
          minLength: 20
          type: string
          description: When the KPI breach occurred
          format: date-time
          example: '2025-09-22T11:00:00.000Z'
        casePriority:
          $ref: '#/components/schemas/KPIPriority'
        createdAt:
          maxLength: 30
          minLength: 20
          type: string
          description: When the breached KPI record was created
          format: date-time
          example: '2025-09-22T11:00:00.000Z'
        id:
          maxLength: 36
          minLength: 36
          pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
          type: string
          description: Unique identifier for the breached KPI
          example: 3f166e9f-3c88-4af2-b52e-138f339dab3e
        kpiType:
          $ref: '#/components/schemas/KPIType'
      description: >-
        Breached KPI details, including the type of KPI, the case priority at
        the time of breach, and when the breach occurred together with current
        status. This information helps understand which KPIs were not met for a
        case and when.
      externalDocs:
        url: ''
    OllyAnalysisPayload:
      title: Olly analysis payload
      type: object
      properties:
        generatedAt:
          maxLength: 30
          minLength: 20
          type: string
          description: Timestamp when the analysis was generated.
          format: date-time
          example: '2025-09-22T10:30:00.000Z'
        investigationSummary:
          maxLength: 8192
          minLength: 1
          pattern: ^[\s\S]*$
          type: string
          description: Natural-language summary of the Olly investigation.
          example: >-
            Latency spike on checkout-service correlates with a deploy of v1.42
            and elevated DB pool saturation.
        remediationRecommendations:
          maxItems: 50
          minItems: 0
          type: array
          items:
            maxLength: 2048
            minLength: 1
            pattern: ^[\s\S]*$
            type: string
            description: Ordered list of remediation steps, one recommendation per element.
          description: Ordered list of remediation steps, one recommendation per element.
          example:
            - Roll back checkout-service to v1.41
            - Increase orders Postgres pool size to 200
        rootCause:
          maxLength: 4096
          minLength: 1
          pattern: ^[\s\S]*$
          type: string
          description: Olly's hypothesised root cause for the case.
          example: Connection-pool exhaustion on the orders Postgres instance.
        rootCauseConfidence:
          $ref: '#/components/schemas/OllyAnalysisRootCauseConfidence'
      description: >-
        Typed analysis payload returned by Olly. Present only when status =
        STATUS_OK.
      externalDocs:
        url: ''
    OllyAnalysisStatus:
      enum:
        - STATUS_UNSPECIFIED
        - STATUS_OK
        - STATUS_CAPACITY_REACHED
        - STATUS_FAILED
      type: string
      description: Olly analysis outcome status.
    CaseResolver:
      title: Case resolver
      type: object
      oneOf:
        - required:
            - system
          type: object
        - required:
            - cxUser
          type: object
        - required:
            - serviceNow
          type: object
        - required:
            - apiKey
          type: object
        - required:
            - slack
          type: object
        - required:
            - prometheusAlertManager
          type: object
        - required:
            - pagerDuty
          type: object
        - required:
            - microsoftTeams
          type: object
        - type: object
          not:
            anyOf:
              - required:
                  - system
                type: object
              - required:
                  - cxUser
                type: object
              - required:
                  - serviceNow
                type: object
              - required:
                  - apiKey
                type: object
              - required:
                  - slack
                type: object
              - required:
                  - prometheusAlertManager
                type: object
              - required:
                  - pagerDuty
                type: object
              - required:
                  - microsoftTeams
                type: object
      properties:
        apiKey:
          $ref: '#/components/schemas/CaseResolver.ApiKey'
        cxUser:
          $ref: '#/components/schemas/CoralogixUser'
        microsoftTeams:
          $ref: '#/components/schemas/MicrosoftTeams'
        pagerDuty:
          $ref: '#/components/schemas/PagerDuty'
        prometheusAlertManager:
          $ref: '#/components/schemas/PrometheusAlertManager'
        serviceNow:
          $ref: '#/components/schemas/ServiceNow'
        slack:
          $ref: '#/components/schemas/Slack'
        system:
          $ref: '#/components/schemas/System'
      description: Entity responsible for resolving the case.
      externalDocs:
        url: ''
    AlertGroupingType:
      title: Alert grouping type
      enum:
        - GROUPING_TYPE_UNSPECIFIED
        - GROUPING_TYPE_COMPOSITE_ALERT
        - GROUPING_TYPE_COMBINATION_ALERT
        - GROUPING_TYPE_NONE
      type: string
      description: >-
        Indicates how this indicator relates to other alerts (composite,
        combination, or none).
    AlertIndicator.Permutation:
      title: Alert permutation
      type: object
      properties:
        permutation:
          type: object
          additionalProperties:
            minLength: 0
            type: string
          description: A single permutation represented as map<string, string>.
      description: >-
        Single alert permutation captured as a map of label keys to label
        values.
      externalDocs:
        url: ''
    IndicatorPriority:
      title: Indicator priority
      enum:
        - INDICATOR_PRIORITY_UNSPECIFIED
        - INDICATOR_PRIORITY_P1
        - INDICATOR_PRIORITY_P2
        - INDICATOR_PRIORITY_P3
        - INDICATOR_PRIORITY_P4
        - INDICATOR_PRIORITY_P5
      type: string
      description: Priority of an alert indicator at trigger time.
    IndicatorState:
      title: Indicator state
      enum:
        - INDICATOR_STATE_UNSPECIFIED
        - INDICATOR_STATE_TRIGGERED
        - INDICATOR_STATE_RESOLVED
        - INDICATOR_STATE_NO_DATA
      type: string
      description: Current lifecycle state of an alert indicator.
    AlertSuppression:
      title: Alert suppression details
      type: object
      oneOf:
        - required:
            - activeSuppressionRules
          type: object
        - required:
            - alertDefinitionMuted
          type: object
        - type: object
          not:
            anyOf:
              - required:
                  - activeSuppressionRules
                type: object
              - required:
                  - alertDefinitionMuted
                type: object
      properties:
        activeSuppressionRules:
          $ref: '#/components/schemas/ActiveSuppressionRules'
        alertDefinitionMuted:
          $ref: '#/components/schemas/AlertDefinitionMuted'
        suppressedTime:
          maxLength: 30
          minLength: 20
          type: string
          description: Timestamp when the alert got suppressed.
          format: date-time
          example: '2025-09-22T10:30:00.000Z'
      description: >-
        Data describing the suppression status of an alert indicator, including
        active suppression rules and muted state.
      externalDocs:
        url: ''
    EntityLink:
      title: Entity link
      required:
        - url
      type: object
      properties:
        url:
          maxLength: 2048
          minLength: 1
          pattern: ^[\s\S]*$
          type: string
          description: URL to the entity in the originating system.
          example: https://app.coralogix.com/error-tracking/issues/abc123
      description: A URL reference to an entity in the originating system.
      externalDocs:
        url: ''
    GenericIndicatorType:
      title: Generic indicator type
      enum:
        - GENERIC_INDICATOR_TYPE_UNSPECIFIED
        - GENERIC_INDICATOR_TYPE_ERROR_TRACKING
      type: string
      description: Sub-type of a generic indicator.
    GenericIndicatorStatus:
      title: Generic indicator status
      enum:
        - GENERIC_INDICATOR_STATUS_UNSPECIFIED
        - GENERIC_INDICATOR_STATUS_TRIGGERED
        - GENERIC_INDICATOR_STATUS_RESOLVED
      type: string
      description: Lifecycle status of a generic indicator.
    PrometheusAlert:
      title: Prometheus alert
      required:
        - alertGroupId
        - alertName
        - fingerprint
        - priority
        - labels
        - annotations
        - status
        - generatorUrl
        - createdAt
        - updatedAt
      type: object
      properties:
        alertGroupId:
          maxLength: 256
          minLength: 1
          pattern: ^[\s\S]*$
          type: string
          description: Identifier of the Prometheus alerts group this alert belongs to.
          example: 5d41402abc4b2a76b9719d911017c592
        alertName:
          maxLength: 256
          minLength: 1
          pattern: ^[\s\S]*$
          type: string
          description: Name of the alert (typically the `alertname` label).
          example: HighRequestLatency
        annotations:
          type: object
          additionalProperties:
            minLength: 0
            type: string
          description: Annotations attached to the alert.
        createdAt:
          maxLength: 30
          minLength: 20
          type: string
          description: Timestamp when the alert was first observed.
          format: date-time
          example: '2025-09-22T10:30:00.000Z'
        fingerprint:
          maxLength: 256
          minLength: 1
          pattern: ^[\s\S]*$
          type: string
          description: >-
            Prometheus alert fingerprint (stable identifier for this alert
            instance).
          example: a1b2c3d4e5f6a7b8
        generatorUrl:
          maxLength: 4096
          minLength: 1
          pattern: ^[\s\S]*$
          type: string
          description: URL of the system that generated the alert.
          example: https://prometheus.example.com/graph?g0.expr=...
        labels:
          type: object
          additionalProperties:
            minLength: 0
            type: string
          description: Labels attached to the alert.
        priority:
          $ref: '#/components/schemas/IndicatorPriority'
        query:
          $ref: '#/components/schemas/PrometheusAlertQuery'
        status:
          $ref: '#/components/schemas/PrometheusAlertStatus'
        updatedAt:
          maxLength: 30
          minLength: 20
          type: string
          description: Timestamp when the alert was last updated.
          format: date-time
          example: '2025-09-22T11:05:00.000Z'
      description: Data describing a single Prometheus alert within an alert group.
      externalDocs:
        url: ''
    PrometheusAlertStatus:
      title: Prometheus alert status
      type: object
      oneOf:
        - required:
            - triggered
          type: object
        - required:
            - resolved
          type: object
        - type: object
          not:
            anyOf:
              - required:
                  - triggered
                type: object
              - required:
                  - resolved
                type: object
      properties:
        resolved:
          $ref: '#/components/schemas/Resolved'
        triggered:
          $ref: '#/components/schemas/Triggered'
      description: Lifecycle status of a Prometheus alert or alert group.
      externalDocs:
        url: ''
    BreachStatus:
      title: Breach status
      enum:
        - BREACH_STATUS_UNSPECIFIED
        - BREACH_STATUS_BREACHED
        - BREACH_STATUS_MITIGATED
      type: string
      description: Status of a KPI breach (e.g., still breached or mitigated).
    KPIPriority:
      title: KPI priority
      enum:
        - KPI_PRIORITY_UNSPECIFIED
        - KPI_PRIORITY_P1
        - KPI_PRIORITY_P2
        - KPI_PRIORITY_P3
        - KPI_PRIORITY_P4
        - KPI_PRIORITY_P5
      type: string
      description: Case priority level used when evaluating KPIs.
    KPIType:
      enum:
        - KPI_TYPE_UNSPECIFIED
        - KPI_TYPE_TIME_TO_ACKNOWLEDGE
        - KPI_TYPE_TIME_TO_RESOLVE
        - KPI_TYPE_TIME_TO_UPDATE
      type: string
      description: Kpi type.
    OllyAnalysisRootCauseConfidence:
      enum:
        - OLLY_ANALYSIS_ROOT_CAUSE_CONFIDENCE_UNSPECIFIED
        - OLLY_ANALYSIS_ROOT_CAUSE_CONFIDENCE_LOW
        - OLLY_ANALYSIS_ROOT_CAUSE_CONFIDENCE_MEDIUM
        - OLLY_ANALYSIS_ROOT_CAUSE_CONFIDENCE_HIGH
      type: string
      description: Confidence level Olly assigns to the root-cause hypothesis.
    CaseResolver.ApiKey:
      title: API key resolver
      type: object
      additionalProperties: false
      description: Marker indicating that the case was resolved using an API key.
      externalDocs:
        url: ''
    CoralogixUser:
      title: Coralogix user resolver
      type: object
      additionalProperties: false
      description: Marker indicating that the case was resolved by a Coralogix user.
      externalDocs:
        url: ''
    MicrosoftTeams:
      title: Microsoft Teams resolver
      type: object
      additionalProperties: false
      description: >-
        Marker indicating that the case was resolved through a Microsoft Teams
        integration.
      externalDocs:
        url: ''
    PagerDuty:
      title: PagerDuty resolver
      type: object
      additionalProperties: false
      description: >-
        Marker indicating that the case was resolved through a PagerDuty
        integration.
      externalDocs:
        url: ''
    PrometheusAlertManager:
      title: Prometheus AlertManager resolver
      type: object
      additionalProperties: false
      description: >-
        Marker indicating that the case was resolved through a Prometheus
        AlertManager integration.
      externalDocs:
        url: ''
    ServiceNow:
      title: ServiceNow resolver
      type: object
      additionalProperties: false
      description: >-
        Marker indicating that the case was resolved through a ServiceNow
        integration.
      externalDocs:
        url: ''
    Slack:
      title: Slack resolver
      type: object
      additionalProperties: false
      description: >-
        Marker indicating that the case was resolved through a Slack
        integration.
      externalDocs:
        url: ''
    System:
      title: System resolver
      type: object
      additionalProperties: false
      description: >-
        Marker indicating that the case was resolved automatically by the Cases
        system.
      externalDocs:
        url: ''
    ActiveSuppressionRules:
      title: Active suppression rules
      required:
        - suppressionRuleIds
      type: object
      properties:
        suppressionRuleIds:
          maxItems: 1000
          minItems: 0
          type: array
          items:
            maxLength: 36
            minLength: 36
            pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
            type: string
            description: >-
              Array of active suppression rule IDs for the given alert
              definition.
          description: Array of active suppression rule IDs for the given alert definition.
          example:
            - 1eae3615-79e7-4b54-88e0-6a77def653bf
            - 2fbf4726-8af8-5c65-99f1-7b88ef764c0e
      description: Data describing the active suppression rules for an alert indicator.
      externalDocs:
        url: ''
    AlertDefinitionMuted:
      title: Alert definition is muted
      type: object
      additionalProperties: false
      description: >-
        Object indicating the muted state of the alert definition for an alert
        indicator.
      externalDocs:
        url: ''
    PrometheusAlertQuery:
      title: Prometheus alert query
      required:
        - promql
      type: object
      properties:
        promql:
          maxLength: 4096
          minLength: 1
          pattern: ^[\s\S]*$
          type: string
          description: PromQL expression that triggered the alert.
          example: >-
            histogram_quantile(0.95,
            rate(http_request_duration_seconds_bucket[5m])) > 1
      description: Query backing a Prometheus alert.
      externalDocs:
        url: ''
    Resolved:
      title: Resolved Prometheus alert status
      required:
        - triggeredAt
        - resolvedAt
      type: object
      properties:
        resolvedAt:
          maxLength: 30
          minLength: 20
          type: string
          description: Timestamp when the alert was resolved.
          format: date-time
          example: '2025-09-22T11:05:00.000Z'
        triggeredAt:
          maxLength: 30
          minLength: 20
          type: string
          description: Timestamp when the alert was originally triggered.
          format: date-time
          example: '2025-09-22T10:30:00.000Z'
      description: Status payload for a resolved Prometheus alert.
      externalDocs:
        url: ''
    Triggered:
      title: Triggered Prometheus alert status
      required:
        - triggeredAt
      type: object
      properties:
        triggeredAt:
          maxLength: 30
          minLength: 20
          type: string
          description: Timestamp when the alert was triggered.
          format: date-time
          example: '2025-09-22T10:30:00.000Z'
      description: Status payload for an active Prometheus alert.
      externalDocs:
        url: ''
  securitySchemes:
    apiKeyAuth:
      type: apiKey
      in: header
      name: Authorization
      description: API key authentication

````