# Kibana rule creation fails using REST API

**URL:** <https://discuss.elastic.co/t/kibana-rule-creation-fails-using-rest-api/296771>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [February 9, 2022, 5:47pm UTC](https://discuss.elastic.co/t/kibana-rule-creation-fails-using-rest-api/296771 "2022-02-09T17:47:35Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![umesh2020](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/umesh2020/32/126038_2.png) [@umesh2020](https://discuss.elastic.co/u/umesh2020)\
**Post date:** [February 9, 2022, 5:47pm UTC](https://discuss.elastic.co/t/kibana-rule-creation-fails-using-rest-api/296771/1 "2022-02-09T17:47:35Z")

</div>

I am trying to create a rule using REST API. I tried using curl and also using the console. I get the following error when I try to create the rule.

[types removal] Specifying types in document index requests is deprecated, use the typeless endpoints instead (/{index}/\_doc/{id}, /{index}/\_doc, or /{index}/\_create/{id}).

I copy pasted the rule from the link [Create rule API | Kibana Guide [7.17] | Elastic](https://www.elastic.co/guide/en/kibana/current/create-rule-api.html#create-rule-api-example)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/1/c1e5bc536051b3bbbde22a025ca8a9598f2de0bc.png)  
 ![Screen Shot 2022-02-09 at 12.49.12 PM](https://us1.discourse-cdn.com/elastic/original/3X/3/0/30fb0d0cc46082372565fd80d125c1fd30957fd1.jpeg)

---

<div class="post-metadata">

**Author:** ![Patrick\_Mueller](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrick_mueller/32/109425_2.png) [@Patrick\_Mueller](https://discuss.elastic.co/u/Patrick_Mueller)\
**Post date:** [February 9, 2022, 5:59pm UTC](https://discuss.elastic.co/t/kibana-rule-creation-fails-using-rest-api/296771/2 "2022-02-09T17:59:30Z")

</div>

The Dev Tools console can only be used to send requests to Elasticsearch, but the API you're wanting to use is available at the Kibana server, not the Elasticsearch server. You'll have to use a tool like `curl`, Postman, etc, to send the HTTP request to Kibana.

---

<div class="post-metadata">

**Author:** ![umesh2020](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/umesh2020/32/126038_2.png) [@umesh2020](https://discuss.elastic.co/u/umesh2020)\
**Post date:** [February 9, 2022, 6:04pm UTC](https://discuss.elastic.co/t/kibana-rule-creation-fails-using-rest-api/296771/3 "2022-02-09T18:04:29Z")

</div>

> [@Patrick\_Mueller](#):
>
> curl

If I use the curl, I am getting HTTP/1.1 400 Bad Request. If I look at kibana, logs I see the following error.

```auto
{"type":"error","@timestamp":"2022-02-09T12:02:09-06:00","tags":["connection","client","error"],"pid":18745,"level":"error","error":{"message":"Parse Error: Expected HTTP/","name":"Error","stack":"Error: Parse Error: Expected HTTP/","code":"HPE_INVALID_CONSTANT"},"message":"Parse Error: Expected HTTP/"}

```

---

<div class="post-metadata">

**Author:** ![Patrick\_Mueller](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrick_mueller/32/109425_2.png) [@Patrick\_Mueller](https://discuss.elastic.co/u/Patrick_Mueller)\
**Post date:** [February 9, 2022, 6:29pm UTC](https://discuss.elastic.co/t/kibana-rule-creation-fails-using-rest-api/296771/4 "2022-02-09T18:29:00Z")

</div>

Can you supply the entire `curl` command you ran?

---

<div class="post-metadata">

**Author:** ![umesh2020](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/umesh2020/32/126038_2.png) [@umesh2020](https://discuss.elastic.co/u/umesh2020)\
**Post date:** [February 9, 2022, 6:41pm UTC](https://discuss.elastic.co/t/kibana-rule-creation-fails-using-rest-api/296771/5 "2022-02-09T18:41:40Z")

</div>

```auto
curl -u elastic:xxxx -i -k -X POST "https://10.100.1.197:5601/api/alerting/rule -H 'kbn-xsrf: true' -H 'Content-Type: application/json' -d '" -H 'kbn-xsrf: true' -H 'Content-Type: application/json' -d'
{
  "params":{
      "aggType":"avg",
      "termSize":6,
      "thresholdComparator":">",
      "timeWindowSize":5,
      "timeWindowUnit":"m",
      "groupBy":"top",
      "threshold":[
         1000
      ],
      "index":[
         ".test-index"
      ],
      "timeField":"@timestamp",
      "aggField":"sheet.version",
      "termField":"name.keyword"
   },
   "consumer":"alerts",
   "rule_type_id":".index-threshold",
   "schedule":{
      "interval":"1m"
   },
   "actions":[
      {
         "id":"dceeb5d0-6b41-11eb-802b-85b0c1bc8ba2",
         "group":"threshold met",
         "params":{
            "level":"info",
            "message":"alert {{alertName}} is active for group {{context.group}}:\n\n- Value: {{context.value}}\n- Conditions Met: {{context.con
ditions}} over {{params.timeWindowSize}}{{params.timeWindowUnit}}\n- Timestamp: {{context.date}}"
         }
      }
   ],
   "tags":[
      "cpu"
   ],
   "notify_when":"onActionGroupChange",
   "name":"my alert"
}
'

```

---

<div class="post-metadata">

**Author:** ![Patrick\_Mueller](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrick_mueller/32/109425_2.png) [@Patrick\_Mueller](https://discuss.elastic.co/u/Patrick_Mueller)\
**Post date:** [February 9, 2022, 7:05pm UTC](https://discuss.elastic.co/t/kibana-rule-creation-fails-using-rest-api/296771/6 "2022-02-09T19:05:59Z")

</div>

There's a typo in your curl invocation (the - extra `-d '"` after the content-type header), and the JSON has a new line between `con` and `ditions` in the actions. Other than that, the request worked for me, though it did not recognize the action id 🙂 .

---

<div class="post-metadata">

**Author:** ![umesh2020](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/umesh2020/32/126038_2.png) [@umesh2020](https://discuss.elastic.co/u/umesh2020)\
**Post date:** [February 9, 2022, 7:41pm UTC](https://discuss.elastic.co/t/kibana-rule-creation-fails-using-rest-api/296771/7 "2022-02-09T19:41:55Z")

</div>

Thanks a lot. Can you post your file please ? If I remove the -d '', and remove the new line between con and ditions, I am getting the following error.  
line 39: unexpected EOF while looking for matching `"'  
line 42: syntax error: unexpected end of file

---

<div class="post-metadata">

**Author:** ![umesh2020](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/umesh2020/32/126038_2.png) [@umesh2020](https://discuss.elastic.co/u/umesh2020)\
**Post date:** [February 9, 2022, 8:19pm UTC](https://discuss.elastic.co/t/kibana-rule-creation-fails-using-rest-api/296771/8 "2022-02-09T20:19:38Z")

</div>

I figured out the error. Also, the extra -d '" is coming if I click on copy link as curl in the example ( [Create rule API | Kibana Guide [7.17] | Elastic](https://www.elastic.co/guide/en/kibana/current/create-rule-api.html#create-rule-api-example) )

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 9, 2022, 8:20pm UTC](https://discuss.elastic.co/t/kibana-rule-creation-fails-using-rest-api/296771/9 "2022-03-09T20:20:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
