list_thresholds
const url = 'https://example.com/api/v1/thresholds';const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://example.com/api/v1/thresholds \ --header 'Authorization: Bearer <token>'Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Query Parameters
Section titled “Query Parameters”Case-insensitive substring of the metric name.
Comma-separated scope levels (global | profile | group | group_id | node |
interface); empty or absent means every level.
Comma-separated directions (above | below); empty or absent means both.
true to fill overridden. Off by default: the count walks every node.
Responses
Section titled “Responses”A capped page of matching rules, with the matching total
A capped page of threshold rules.
total is the count of rules matching the filter, not items.len(), so the UI can say how
many it is not showing. truncated is derived rather than left to the client comparing the
two — a client that forgets the comparison shows a complete-looking list.
object
A stored threshold rule with its scope and id (id is for the API; the engine ignores it).
object
Value at/above which the node is Critical. None = no upper critical bound.
Value at/below which the node is Critical. None = no lower critical bound.
Hysteresis: consecutive samples the breach must hold before transitioning,
to damp oscillation at the threshold. 0/1 = transition immediately.
Stable metric name this rule applies to (e.g. cpu_util).
Value at/above which the node is Warning. None = no upper warning bound.
Value at/below which the node is Warning. None = no lower warning bound.
The primary side’s critical bound. See direction.
Which way this rule’s warning/critical face. Superseded by the four bounds on the rule
itself, which describe both sides; on a rule bounding both, this names the primary side
only and describes half of what the rule does.
Which rows of a vendor table this rule applies to, by the row’s name — I/O, or
MPU Board *. Case-insensitive, and * matches any run of characters. Absent means every
row, and every metric that has no rows. At the same scope, a rule with a pattern wins over
one without for the rows it matches.
Every profile, folder group, node or port this rule applies to — scope_level says which
of those they are. Empty for a global rule, which applies to every node.
The scope a threshold is defined at, ordered least → most specific: Interface (one port)
wins over Node, which wins over a folder group, which wins over Group, which wins over
Profile, which wins over Global (every node).
The primary side’s warning bound. See direction.
For each rule in items that is overridden somewhere: on how many nodes a narrower rule on
the same metric applies instead. A rule overridden nowhere has no entry.
Filled only when the request asks with overridden=true; empty otherwise, because the count
walks the whole fleet and a caller that wants only total should not pay for it.
Counted across the whole fleet, regardless of the filter and the cap. The unit is the node: a node counts once even when the narrower rule covers only some of its ports or table rows. Rules at the same scope level combine rather than override, so they do not count against each other — except folder rules, where only the nearest folder’s is in force, so a parent folder’s rule counts as overridden on the nodes a child folder’s rule reaches. Which nodes a profile, label or folder holds is read from the alert engine’s copy, which can be up to about 30 seconds old.
object
For each port-level rule in items whose port has a known name: the scope id
(<node-uuid>:<ifindex>) mapped to the port’s name (ifName), read from the interface
inventory the same way an alert’s if_name is (ADR-196 decision 6). A port with no known
name has no entry and is shown by its ifIndex.
object
Rules matching the filter, ignoring the cap.
Whether items is a prefix of the matching rules rather than all of them.
Example
{ "items": [ { "direction": "above", "scope_level": "global" } ]}scope_level or direction names a value outside its vocabulary
The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI
document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies
undescribed — a client that has to guess the failure shape ends up parsing the success shape and
reading undefined.
object
object
Stable machine-readable code. Clients branch on this, never on the message.
Operator-facing sentence. Safe to display; never carries an internal error’s own text.
Examplegenerated
{ "error": { "code": "example", "message": "example" }}No valid bearer token
The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI
document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies
undescribed — a client that has to guess the failure shape ends up parsing the success shape and
reading undefined.
object
object
Stable machine-readable code. Clients branch on this, never on the message.
Operator-facing sentence. Safe to display; never carries an internal error’s own text.
Examplegenerated
{ "error": { "code": "example", "message": "example" }}Role lacks ManageConfig — the ruleset decides when the fleet pages someone
The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI
document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies
undescribed — a client that has to guess the failure shape ends up parsing the success shape and
reading undefined.
object
object
Stable machine-readable code. Clients branch on this, never on the message.
Operator-facing sentence. Safe to display; never carries an internal error’s own text.
Examplegenerated
{ "error": { "code": "example", "message": "example" }}Skeleton mode has no write side
The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI
document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies
undescribed — a client that has to guess the failure shape ends up parsing the success shape and
reading undefined.
object
object
Stable machine-readable code. Clients branch on this, never on the message.
Operator-facing sentence. Safe to display; never carries an internal error’s own text.
Examplegenerated
{ "error": { "code": "example", "message": "example" }}