Method: alertGroupingRules.create

Full name: projects.locations.instances.alertGroupingRules.create

Creates a new alert grouping rule. Defines new criteria for alert aggregation, specifying how future incoming alerts should be consolidated into cases based on shared attributes or entity correlations.

HTTP request


POST https://chronicle.africa-south1.rep.googleapis.com/v1beta/{parent}/alertGroupingRules

Path parameters

Parameters
parent

string

Required. The parent resource where this AlertGroupingRule will be created. Format: projects/{project}/locations/{location}/instances/{instance}

Request body

The request body contains an instance of AlertGroupingRule.

Response body

If successful, the response body contains a newly created instance of AlertGroupingRule.

Authorization scopes

Requires one of the following OAuth scopes:

  • https://www.googleapis.com/auth/cloud-platform
  • https://www.googleapis.com/auth/chronicle
  • https://www.googleapis.com/auth/chronicle.readonly

For more information, see the Authentication Overview.

IAM Permissions

Requires the following IAM permission on the parent resource:

  • chronicle.alertGroupingRules.update

For more information, see the IAM documentation.