Create a monitor
POST {{baseUrl}}/api/v1/monitor
Create a monitor using the specified options.
Monitor Types
The type of monitor chosen from:
- anomaly:
query alert - APM:
query alertortrace-analytics alert - composite:
composite - custom:
service check - event:
event alert - forecast:
query alert - host:
service check - integration:
query alertorservice check - live process:
process alert - logs:
log alert - metric:
query alert - network:
service check - outlier:
query alert - process:
service check - rum:
rum alert - SLO:
slo alert - watchdog:
event-v2 alert - event-v2:
event-v2 alert - audit:
audit alert - error-tracking:
error-tracking alert - database-monitoring:
database-monitoring alert
Notes: - Synthetic monitors are created through the Synthetics API. See the Synthetics API documentation for more information. - Log monitors require an unscoped App Key.
Query Types
Metric Alert Query
Example: time_aggr(time_window):space_aggr:metric{tags} [by {key}] operator #
time_aggr: avg, sum, max, min, change, or pct_changetime_window:last_#m(with#between 1 and 10080 depending on the monitor type) orlast_#h(with#between 1 and 168 depending on the monitor type) orlast_1d, orlast_1wspace_aggr: avg, sum, min, or maxtags: one or more tags (comma-separated), or *key: a 'key' in key:value tag syntax; defines a separate alert for each tag in the group (multi-alert)operator: <, <=, >, >=, ==, or !=#: an integer or decimal number used to set the threshold
If you are using the _change_ or _pct_change_ time aggregator, instead use change_aggr(time_aggr(time_window),
timeshift):space_aggr:metric{tags} [by {key}] operator # with:
change_aggrchange, pct_changetime_aggravg, sum, max, min Learn moretime_windowlast_#m (between 1 and 2880 depending on the monitor type), last_#h (between 1 and 48 depending on the monitor type), or last_#d (1 or 2)timeshift#mago (5, 10, 15, or 30), #hago (1, 2, or 4), or 1d_ago
Use this to create an outlier monitor using the following query:
avg(last_30m):outliers(avg:system.cpu.user{role:es-events-data} by {host}, 'dbscan', 7) > 0
Service Check Query
Example: "check".over(tags).last(count).by(group).count_by_status()
checkname of the check, for exampledatadog.agent.uptagsone or more quoted tags (comma-separated), or*
. for example:.over("env:prod", "role:db");overcannot be blank.countmust be at greater than or equal to your max threshold (defined in theoptions). It is limited to 100. For example, if you've specified to notify on 1 critical, 3 ok, and 2 warn statuses,countshould be at least 3.groupmust be specified for check monitors. Per-check grouping is already explicitly known for some service checks. For example, Postgres integration monitors are tagged bydb,host, andport, and Network monitors byhost,instance, andurl. See Service Checks documentation for more information.
Event Alert Query
Note: The Event Alert Query has been replaced by the Event V2 Alert Query. For more information, see the Event Migration guide.
Event V2 Alert Query
Example: events(query).rollup(rollup_method[, measure]).last(time_window) operator #
queryThe search query - following the Log search syntax.rollup_methodThe stats roll-up method - supportscount,avgandcardinality.measureForavgand cardinalityrollup_method- specify the measure or the facet name you want to use.time_window#m (between 1 and 2880), #h (between 1 and 48).operator<,<=,>,>=,==, or!=.#an integer or decimal number used to set the threshold.
Process Alert Query
Example: processes(search).over(tags).rollup('count').last(timeframe) operator #
searchfree text search string for querying processes. Matching processes match results on the Live Processes page.tagsone or more tags (comma-separated)timeframethe timeframe to roll up the counts. Examples: 10m, 4h. Supported timeframes: s, m, h and doperator<, <=, >, >=, ==, or !=#an integer or decimal number used to set the threshold
Logs Alert Query
Example: logs(query).index(index_name).rollup(rollup_method[, measure]).last(time_window) operator #
queryThe search query - following the Log search syntax.index_nameFor multi-index organizations, the log index in which the request is performed.rollup_methodThe stats roll-up method - supportscount,avgandcardinality.measureForavgand cardinalityrollup_method- specify the measure or the facet name you want to use.time_window#m (between 1 and 2880), #h (between 1 and 48).operator<,<=,>,>=,==, or!=.#an integer or decimal number used to set the threshold.
Composite Query
Example: 12345 && 67890, where 12345 and 67890 are the IDs of non-composite monitors
name[required, default = dynamic, based on query]: The name of the alert.message[required, default = dynamic, based on query]: A message to include with notifications for this monitor. Email notifications can be sent to specific users by using the same '@username' notation as events.tags[optional, default = empty list]: A list of tags to associate with your monitor. When getting all monitor details via the API, use themonitor_tagsargument to filter results by these tags. It is only available via the API and isn't visible or editable in the Datadog UI.
SLO Alert Query
Example: error_budget("slo_id").over("time_window") operator #
slo_id: The alphanumeric SLO ID of the SLO you are configuring the alert for.time_window: The time window of the SLO target you wish to alert on. Valid options:7d,30d,90d.operator:>=or>
Audit Alert Query
Example: audits(query).rollup(rollup_method[, measure]).last(time_window) operator #
queryThe search query - following the Log search syntax.rollup_methodThe stats roll-up method - supportscount,avgandcardinality.measureForavgand cardinalityrollup_method- specify the measure or the facet name you want to use.time_window#m (between 1 and 2880), #h (between 1 and 48).operator<,<=,>,>=,==, or!=.#an integer or decimal number used to set the threshold.
CI Pipelines Alert Query
Example: ci-pipelines(query).rollup(rollup_method[, measure]).last(time_window) operator #
queryThe search query - following the Log search syntax.rollup_methodThe stats roll-up method - supportscount,avg, andcardinality.measureForavgand cardinalityrollup_method- specify the measure or the facet name you want to use.time_window#m (between 1 and 2880), #h (between 1 and 48).operator<,<=,>,>=,==, or!=.#an integer or decimal number used to set the threshold.
CI Tests Alert Query
Example: ci-tests(query).rollup(rollup_method[, measure]).last(time_window) operator #
queryThe search query - following the Log search syntax.rollup_methodThe stats roll-up method - supportscount,avg, andcardinality.measureForavgand cardinalityrollup_method- specify the measure or the facet name you want to use.time_window#m (between 1 and 2880), #h (between 1 and 48).operator<,<=,>,>=,==, or!=.#an integer or decimal number used to set the threshold.
Error Tracking Alert Query
Example(RUM): error-tracking-rum(query).rollup(rollup_method[, measure]).last(time_window) operator #
Example(APM Traces): error-tracking-traces(query).rollup(rollup_method[, measure]).last(time_window) operator #
queryThe search query - following the Log search syntax.rollup_methodThe stats roll-up method - supportscount,avg, andcardinality.measureForavgand cardinalityrollup_method- specify the measure or the facet name you want to use.time_window#m (between 1 and 2880), #h (between 1 and 48).operator<,<=,>,>=,==, or!=.#an integer or decimal number used to set the threshold.
Database Monitoring Alert Query
Example: database-monitoring(query).rollup(rollup_method[, measure]).last(time_window) operator #
queryThe search query - following the Log search syntax.rollup_methodThe stats roll-up method - supportscount,avg, andcardinality.measureForavgand cardinalityrollup_method- specify the measure or the facet name you want to use.time_window#m (between 1 and 2880), #h (between 1 and 48).operator<,<=,>,>=,==, or!=.#an integer or decimal number used to set the threshold.
Request Body
{"message"=>"You may need to add web hosts if this is consistently high.", "name"=>"Bytes received on host0", "options"=>{"no_data_timeframe"=>20, "notify_no_data"=>true}, "query"=>"avg(last_5m):sum:system.net.bytes_rcvd{host:host0} > 100", "tags"=>["app:webserver", "frontend"], "type"=>"query alert"}
HEADERS
| Key | Datatype | Required | Description |
|---|---|---|---|
Content-Type | string | ||
Accept | string |
RESPONSES
status: OK
{"type":"query alert","query":"avg(last_5m):sum:system.net.bytes_rcvd{host:host0} \u003e 100","created":"1977-02-24T00:55:39.149Z","creator":{"email":"eu do sit ex","handle":"aliquip cupidatat ut ut","name":"aute anim esse mollit et"},"deleted":"2005-10-04T10:03:03.282Z","id":-85100539,"matching_downtimes":[{"id":1625,"end":1412792983,"scope":["env:staging"],"start":1412792983},{"id":1625,"end":1412792983,"scope":["env:staging"],"start":1412792983}],"message":"nisi sed Ut","modified":"1994-05-25T16:32:06.852Z","multi":true,"name":"My monitor","options":{"aggregation":{"group_by":"host","metric":"metrics.name","type":"count"},"enable_logs_sample":false,"enable_samples":false,"escalation_message":"sint aliquip","evaluation_delay":-32193217,"group_retention_duration":"sunt magna","groupby_simple_monitor":false,"include_tags":true,"min_failure_duration":0,"min_location_failed":1,"new_group_delay":-74956346,"no_data_timeframe":10290724,"notification_preset_name":"show_all","notify_audit":false,"notify_by":["laboris amet mollit","laboris "],"notify_no_data":false,"on_missing_data":"show_and_notify_no_data","renotify_interval":null,"renotify_occurrences":53731472,"renotify_statuses":["alert","alert"],"require_full_window":false,"scheduling_options":{"custom_schedule":{"recurrences":[{"rrule":"FREQ=WEEKLY;BYDAY=MO,TU,WE,TH,FR","start":"2023-08-31T16:30:00","timezone":"Europe/Paris"},{"rrule":"FREQ=WEEKLY;BYDAY=MO,TU,WE,TH,FR","start":"2023-08-31T16:30:00","timezone":"Europe/Paris"}]},"evaluation_window":{"day_starts":"04:00","hour_starts":0,"month_starts":1}},"threshold_windows":{"recovery_window":"laborum dolor ut","trigger_window":"occaecat veniam"},"thresholds":{"critical":52502101.190716386,"critical_recovery":33037203.80033295,"ok":14658043.747987643,"unknown":2305380.307081431,"warning":54314333.28059968,"warning_recovery":14656234.927481294},"timeout_h":null,"variables":[{"data_source":"rum","compute":{"aggregation":"avg","interval":60000,"metric":"@duration"},"name":"query_errors","group_by":[{"facet":"status","limit":10,"sort":{"aggregation":"avg","metric":"ullamco sunt","order":"desc"}},{"facet":"status","limit":10,"sort":{"aggregation":"avg","metric":"nulla ea aliquip","order":"desc"}}],"indexes":["days-3","days-7"],"search":{"query":"service:query"}},{"data_source":"rum","compute":{"aggregation":"avg","interval":60000,"metric":"@duration"},"name":"query_errors","group_by":[{"facet":"status","limit":10,"sort":{"aggregation":"avg","metric":"sed dolor","order":"desc"}},{"facet":"status","limit":10,"sort":{"aggregation":"avg","metric":"veniam ullamco voluptate magna mollit","order":"desc"}}],"indexes":["days-3","days-7"],"search":{"query":"service:query"}}]},"overall_state":"Warn","priority":2,"restricted_roles":["Lorem exercitation","sunt consectetur Excepteur"],"state":{"groups":{"idd":{"last_nodata_ts":-84384069,"last_notified_ts":-21864917,"last_resolved_ts":-84458867,"last_triggered_ts":97076299,"name":"id mollit commodo","status":"Alert"},"adipisicing_8":{"last_nodata_ts":-58086015,"last_notified_ts":-22268177,"last_resolved_ts":-43962499,"last_triggered_ts":-58469500,"name":"quis","status":"Alert"}}},"tags":["dolor exercitation Lorem veniam","eu cupidat"]}