# Create default monitoring rules

**URL:** <https://discuss.elastic.co/t/create-default-monitoring-rules/328810>\
**Category:** Kibana\
**Tags:** elastic-stack-monitoring\
**Created:** [March 29, 2023, 10:53am UTC](https://discuss.elastic.co/t/create-default-monitoring-rules/328810 "2023-03-29T10:53:32Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![lduvnjak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lduvnjak/32/77724_2.png) [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Post date:** [March 29, 2023, 10:53am UTC](https://discuss.elastic.co/t/create-default-monitoring-rules/328810/1 "2023-03-29T10:53:32Z")

</div>

Hey Everyone,

When enabling monitoring it creates default rules for some standard issues like "shard size too large", "CCR read exception", etc.  
The rules are listed [here](https://www.elastic.co/guide/en/kibana/master/kibana-alerts.html).

What I'm interested in, is how to recreate these rules once deleted. There is apparently an option of sorts when you consult the [documentation](https://www.elastic.co/guide/en/kibana/master/kibana-alerts.html#_create_default_rules), but I can't seem to find it when scrolling through Kibana.

Does someone know where it is, and if it's possible to recreate these rules automatically. Either via API or some CLI commands?

Thanks for any help in advance!

Cheers,  
Luka

---

<div class="post-metadata">

**Author:** ![lduvnjak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lduvnjak/32/77724_2.png) [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Post date:** [March 29, 2023, 1:00pm UTC](https://discuss.elastic.co/t/create-default-monitoring-rules/328810/2 "2023-03-29T13:00:17Z")

</div>

I've managed to find the way you create default rules.  
It's located on **Stack Monitoring** default page, top right under **Alerts and rules** \> **Create default rules**.  
Is there any way to automate it?

Cheers,  
Luka

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 26, 2023, 1:00pm UTC](https://discuss.elastic.co/t/create-default-monitoring-rules/328810/3 "2023-04-26T13:00:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

---

<div class="post-metadata">

**Author:** ![camille\_li](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/camille_li/32/92508_2.png) [@camille\_li](https://discuss.elastic.co/u/camille_li)\
**Post date:** [April 10, 2025, 12:45am UTC](https://discuss.elastic.co/t/create-default-monitoring-rules/328810/4 "2025-04-10T00:45:51Z")

</div>

You can try to run the Kibana API.

```auto
#dev tool example
POST kbn:/api/monitoring/v1/alerts/enable

```
