Skip to main content
POST
Simulate alert rule

Authorizations

Authorization
string
header
required

Use an Observe API key from the management console. The key selects the project and must grant the permission listed on the operation. Keep this key on your server.

Body

application/json
ruleType
enum<string>
required

Type of the rule to simulate.

Available options:
login_success_rate,
flow_volume,
subflow_volume
rule
object
required

The configuration of an alert rule: the generic envelope every rule type shares, plus one settings object belonging to the rule type named by type. Everything outside settings is implemented once, generically - the window is resolved and handed to the rule type as two absolute timestamps, and the conditions are applied to whatever number the rule type returned, so a rule type never sees the thresholds. Shape and vocabulary are validated here. The semantics that span fields - that the bands get stricter as the level does, that recovery sits on the lenient side of them, that the window is a whole number of days, and that groupBy names dimensions this project actually has - are validated when the rule is saved and again when it is evaluated, because only the second catches a project that changed after the rule was written.

toMs
integer<int64>

End of the simulated range in milliseconds since epoch, from the toMs of an earlier simulation of the same rule. Omit it to simulate the seven days up to now. It must have ended within the last 24 hours.

focus
object

Labels of one group, e.g. {"country": "DE"}, whose every step the result carries for a detailed chart. An ungrouped rule's only group has no labels: send {}.

Response

Newline-delimited JSON progress stream; the final line carries the simulation result.

One line of a simulation's progress stream.

type
enum<string>
required

started comes first, progress after every chunk of data read (repeated while a chunk takes long), and either completed with the result or failed last.

Available options:
started,
progress,
completed,
failed
chunksDone
integer

Chunks of data read so far (progress events).

chunksTotal
integer

Chunks of data to read in total (progress events).

simulation
object
message
string

Why the simulation failed (failed events).