コンテンツにスキップ

list_alerts

GET
/api/v1/alerts
curl --request GET \
--url https://example.com/api/v1/alerts \
--header 'Authorization: Bearer <token>'

Every active alert, each decorated with its inbound ack state

Media typeapplication/json
Array

An active alert plus its inbound (read-only) ack state.

subject_kind and subject_name decompose the alert’s node field, which carries either a node’s UUID, pool:<name> or meraki_org:<uuid>. The live alert stream emits the same three keys.

object
at_unix_ms
required

When it fired (Unix ms, UTC).

integer format: int64
breach
One of:
null
check
required

The check that produced it.

string format: uuid
flapping
required

Whether the underlying check is currently flapping.

boolean
ifindex
One of:
null
metric
required

Metric the check measured (e.g. "icmp_rtt_ms"; the liveness sentinel for up/down). Carried for the history log + notification payload so a human can read what fired — not part of alert identity (dedup/grouping ignore it).

string
node
required

What the alert is about: a node’s UUID, or pool:<name> for a poller-pool alert.

string
root_cause
One of:
null
row

The row of a vendor table this alert is about — a memory pool, a CPU, a sensor — as the row key its samples carry; None for an alert about the whole node or about a port.

integer | null format: int32
row_name

What that row was called when the alert fired (I/O, MPU Board 0); None when the row has no name yet or the alert is not about a row.

string | null
severity
required

Severity (derived from the committed state).

string
Allowed values: info warning critical
state
required

The committed state that triggered the alert.

string
Allowed values: ok warning critical unknown unreachable maintenance
acked
One of:
null
if_name

The name of the port a per-port alert is about (ifName), read from the interface inventory when the alert is read rather than stored with it (ADR-196 decision 6). Absent for an alert about no port, and for a port whose name is not known.

string | null
subject_kind
required

What this alert is about: a monitored node, or Yagra’s own polling coverage for a pool.

string
Allowed values: node pool meraki_org
subject_name

The subject’s name, for a subject identified by name rather than by id (a poller pool).

string | null
title

What the alert is called, in English — SNMP not responding rather than snmp_up (ADR-196). The metric’s own name when Yagra has none for it; absent for an alert with no metric at all.

string | null
Example
[
{
"breach": {
"direction": "above"
},
"severity": "info",
"state": "ok",
"subject_kind": "node"
}
]

No valid bearer token

Media typeapplication/json

The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies undescribed — a client that has to guess the failure shape ends up parsing the success shape and reading undefined.

object
error
required
object
code
required

Stable machine-readable code. Clients branch on this, never on the message.

string
message
required

Operator-facing sentence. Safe to display; never carries an internal error’s own text.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example"
}
}

Role lacks the read permission

Media typeapplication/json

The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies undescribed — a client that has to guess the failure shape ends up parsing the success shape and reading undefined.

object
error
required
object
code
required

Stable machine-readable code. Clients branch on this, never on the message.

string
message
required

Operator-facing sentence. Safe to display; never carries an internal error’s own text.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example"
}
}