コンテンツにスキップ

list_thresholds

GET
/api/v1/thresholds
curl --request GET \
--url https://example.com/api/v1/thresholds \
--header 'Authorization: Bearer <token>'
limit
integer format: int64
q
string

Case-insensitive substring of the metric name.

scope_level
string

Comma-separated scope levels (global | profile | group | group_id | node | interface); empty or absent means every level.

direction
string

Comma-separated directions (above | below); empty or absent means both.

overridden
boolean

true to fill overridden. Off by default: the count walks every node.

A capped page of matching rules, with the matching total

Media typeapplication/json

A capped page of threshold rules.

total is the count of rules matching the filter, not items.len(), so the UI can say how many it is not showing. truncated is derived rather than left to the client comparing the two — a client that forgets the comparison shows a complete-looking list.

object
items
required
Array

A stored threshold rule with its scope and id (id is for the API; the engine ignores it).

object
critical_above

Value at/above which the node is Critical. None = no upper critical bound.

number | null format: double
critical_below

Value at/below which the node is Critical. None = no lower critical bound.

number | null format: double
dwell_samples
required

Hysteresis: consecutive samples the breach must hold before transitioning, to damp oscillation at the threshold. 0/1 = transition immediately.

integer format: int32
metric
required

Stable metric name this rule applies to (e.g. cpu_util).

string
warning_above

Value at/above which the node is Warning. None = no upper warning bound.

number | null format: double
warning_below

Value at/below which the node is Warning. None = no lower warning bound.

number | null format: double
critical

The primary side’s critical bound. See direction.

number | null format: double
direction
required

Which way this rule’s warning/critical face. Superseded by the four bounds on the rule itself, which describe both sides; on a rule bounding both, this names the primary side only and describes half of what the rule does.

string
Allowed values: above below
id
required
string format: uuid
row_match

Which rows of a vendor table this rule applies to, by the row’s name — I/O, or MPU Board *. Case-insensitive, and * matches any run of characters. Absent means every row, and every metric that has no rows. At the same scope, a rule with a pattern wins over one without for the rows it matches.

string | null
scope_ids
required

Every profile, folder group, node or port this rule applies to — scope_level says which of those they are. Empty for a global rule, which applies to every node.

Array<string>
scope_level
required

The scope a threshold is defined at, ordered least → most specific: Interface (one port) wins over Node, which wins over a folder group, which wins over Group, which wins over Profile, which wins over Global (every node).

string
Allowed values: global profile group group_id node interface
warning

The primary side’s warning bound. See direction.

number | null format: double
overridden
required

For each rule in items that is overridden somewhere: on how many nodes a narrower rule on the same metric applies instead. A rule overridden nowhere has no entry.

Filled only when the request asks with overridden=true; empty otherwise, because the count walks the whole fleet and a caller that wants only total should not pay for it.

Counted across the whole fleet, regardless of the filter and the cap. The unit is the node: a node counts once even when the narrower rule covers only some of its ports or table rows. Rules at the same scope level combine rather than override, so they do not count against each other — except folder rules, where only the nearest folder’s is in force, so a parent folder’s rule counts as overridden on the nodes a child folder’s rule reaches. Which nodes a profile, label or folder holds is read from the alert engine’s copy, which can be up to about 30 seconds old.

object
key
additional properties
integer format: int32
port_names
required

For each port-level rule in items whose port has a known name: the scope id (<node-uuid>:<ifindex>) mapped to the port’s name (ifName), read from the interface inventory the same way an alert’s if_name is (ADR-196 decision 6). A port with no known name has no entry and is shown by its ifIndex.

object
key
additional properties
string
total
required

Rules matching the filter, ignoring the cap.

integer format: int64
truncated
required

Whether items is a prefix of the matching rules rather than all of them.

boolean
Example
{
"items": [
{
"direction": "above",
"scope_level": "global"
}
]
}

scope_level or direction names a value outside its vocabulary

Media typeapplication/json

The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies undescribed — a client that has to guess the failure shape ends up parsing the success shape and reading undefined.

object
error
required
object
code
required

Stable machine-readable code. Clients branch on this, never on the message.

string
message
required

Operator-facing sentence. Safe to display; never carries an internal error’s own text.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example"
}
}

No valid bearer token

Media typeapplication/json

The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies undescribed — a client that has to guess the failure shape ends up parsing the success shape and reading undefined.

object
error
required
object
code
required

Stable machine-readable code. Clients branch on this, never on the message.

string
message
required

Operator-facing sentence. Safe to display; never carries an internal error’s own text.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example"
}
}

Role lacks ManageConfig — the ruleset decides when the fleet pages someone

Media typeapplication/json

The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies undescribed — a client that has to guess the failure shape ends up parsing the success shape and reading undefined.

object
error
required
object
code
required

Stable machine-readable code. Clients branch on this, never on the message.

string
message
required

Operator-facing sentence. Safe to display; never carries an internal error’s own text.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example"
}
}

Skeleton mode has no write side

Media typeapplication/json

The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies undescribed — a client that has to guess the failure shape ends up parsing the success shape and reading undefined.

object
error
required
object
code
required

Stable machine-readable code. Clients branch on this, never on the message.

string
message
required

Operator-facing sentence. Safe to display; never carries an internal error’s own text.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example"
}
}