Method: alertGroupingRules.patch

Full name: projects.locations.instances.alertGroupingRules.patch

Updates an existing alert grouping rule. Use this method to modify rule criteria, such as the entity types used for correlation or the specific category details like alert types or products included in the rule.

HTTP request


PATCH https://chronicle.africa-south1.rep.googleapis.com/v1alpha/{alertGroupingRule.name}

Path parameters

Parameters
alertGroupingRule.name

string

Identifier. The resource name of the AlertGroupingRule. Format: projects/{project}/locations/{location}/instances/{instance}/alertGroupingRules/{alertGroupingRule}

Query parameters

Parameters
updateMask

string (FieldMask format)

Optional. The list of fields to update. If not included, all fields with a non-empty value will be overwritten.

This is a comma-separated list of fully qualified names of fields. Example: "user.displayName,photo".

Request body

The request body contains an instance of AlertGroupingRule.

Response body

If successful, the response body contains an instance of AlertGroupingRule.

Authorization scopes

Requires one of the following OAuth scopes:

  • https://www.googleapis.com/auth/cloud-platform
  • https://www.googleapis.com/auth/chronicle
  • https://www.googleapis.com/auth/chronicle.readonly

For more information, see the Authentication Overview.

IAM Permissions

Requires the following IAM permission on the name resource:

  • chronicle.alertGroupingRules.update

For more information, see the IAM documentation.