Manage events and alerts

Get information about log events, such as node compactions and repairs, that are triggered through OpsCenter, and configure alert thresholds for database metrics.

Alert rule object

Alert rule objects define the conditions under which alerts are triggered for various events and metrics in OpsCenter.

An alert rule object has the following form:

{
  "id": <value>,
  "type": <value>,
  "threshold": <value>,
  "comparator": <value>,
  "duration": <value>,
  "notify_interval": <value>,
  "enabled": <value>,
  "metric": <value>,
  "cf": <value>,
  "item": <value>,
  "dc": <value>
}

The alert rule object properties are:

Property Type Description of Values

id

String

A unique ID that references an alert rule.

When creating alert rules, omit this property. The system generates this value when an alert rule is created.

When you GET, PUT, or DELETE an alert rule, you use the id property to specify an alert rule.

type

String

The event or metric aggregation that triggers an alert. Accepted values include rolling-avg, cluster-balance, and node-down. This field is immutable after creating the alert rule.

threshold

Float

The metric boundary that triggers the alert. Applicable only when the type is rolling-avg.

comparator

String

Optional comparison operator for setting alert conditions. Accepted values are < (less than) or > (greater than).

duration

Int

The time, in minutes, that a condition must exist before triggering the alert.

notify_interval

Int

The frequency, in minutes, to reissue alert notifications. To notify only once, set notify_interval to 0.

enabled

Int

Activate or deactivate an alert. Set to 0 to disable an alert. Set to 1 to enable an alert.

metric

String

The key of the metric to monitor. For metrics keys, see Metrics attribute key lists. Applicable only when the type is rolling-avg.

cf

String

Optional. The table to monitor if metric is a cf-keys metric. If omitted, all tables are monitored.

item

String

Optional. The device to monitor if metric is an os-keys metric. If omitted, all devices are monitored.

dc

String

Optional. The name of the datacenter that contains nodes to be monitored. If omitted, all nodes are monitored.

GET /{cluster_id}/alert-rules

Retrieve a list of configured alert rules in OpsCenter.

Path arguments:

Returns a list of alert rule objects with the following structure:

Example:

curl http://127.0.0.1:8888/Test_Cluster/alert-rules

Output:

[
  {
    "comparator": ">",
    "dc": "us-east",
    "duration": 1.0,
    "enabled": 1,
    "id": "e0c356c7-62ff-4aa8-9b17-e305f101b69a",
    "metric": "write-latency",
    "notify_interval": 1.0,
    "threshold": 10000.0,
    "type": "rolling-avg"
  },
  ...
]

GET /{cluster_id}/alert-rules/{alert_id}

Retrieve a specific alert rule.

Path arguments:

Returns an alert rule object.

Example:

curl http://127.0.0.1:8888/Test_Cluster/alert-rules/e0c356c7-62ff-4aa8-9b17-e305f101b69a

Output:

{
  "comparator": ">",
  "dc": "us-east",
  "duration": 1.0,
  "enabled": 1,
  "id": "e0c356c7-62ff-4aa8-9b17-e305f101b69a",
  "metric": "write-latency",
  "notify_interval": 1.0,
  "threshold": 10000.0,
  "type": "rolling-avg"
}

POST /{cluster_id}/alert-rules

Create a new alert rule.

Path arguments:

Body: A dictionary in the form of an alert rule object describing the alert to create.

Returns 201 response code and the ID of the newly created alert if successful.

Example:

curl -X POST
http://127.0.0.1:8888/Test_Cluster/alert-rules
-d '{
  "comparator": ">",
  "dc": "",
  "duration": 60.0,
  "enabled": 1,
  "metric": "heap-used",
  "notify_interval": 5.0,
  "threshold": 6291456000.0,
  "type": "rolling-avg"
}'

Output:

"b375fd3e-3908-4be5-ae37-d8f3b8699a9f"

PUT /{cluster_id}/alert-rules/{alert_id}

Update an existing alert rule.

Path arguments:

Body: A dictionary of fields from an alert rule object to update.

Returns 200 response code if the alert rule was updated successfully.

Example:

curl -X PUT
http://127.0.0.1:8888/Test_Cluster/alert-rules/b375fd3e-3908-4be5-ae37-d8f3b8699a9f
-d '{"duration": 120.0}'

DELETE /{cluster_id}/alert-rules/{alert_id}

Delete an existing alert rule.

Path arguments:

Returns 200 response code if the alert rule was removed successfully.

Example:

curl -X DELETE
http://127.0.0.1:8888/Test_Cluster/alert-rules/b375fd3e-3908-4be5-ae37-d8f3b8699a9f

GET /{cluster_id}/events/notifications-enabled

Check whether notifications are enabled globally for a cluster. This setting corresponds to the Notifications Status toggle in the OpsCenter UI under Manage Alert Rules.

Path arguments:

Returns 200 response code and a Boolean: true if notifications are enabled or false if notifications are disabled.

Example:

curl http://127.0.0.1:8888/Test_Cluster/events/notifications-enabled

PUT /{cluster_id}/events/notifications-enabled

Enable or disable notifications globally for a cluster. This setting corresponds to the Notifications Status toggle in the OpsCenter UI under Manage Alert Rules.

Path arguments:

Body: A boolean to enable (true) or disable (false) notifications.

Returns 200 response code if the notifications status was updated successfully.

Example:

curl -X PUT
http://127.0.0.1:8888/Test_Cluster/events/notifications-enabled
-d 'false'

GET /{cluster_id}/events

Retrieve historical events logged by OpsCenter.

Path arguments:

Query parameters:

  • count: The number of events to return. Defaults to 10.

  • timestamp: A timestamp specifying the point in time to start retrieving events. Specified as a Unix timestamp in microseconds. Defaults to the current time.

  • reverse: A boolean (0 or 1) indicating whether to retrieve events in reverse order. Defaults to 1 (true). Events are retrieved starting from the time specified by the timestamp and going backward in time until count events are found or there are no more events to retrieve.

Returns a list of dictionaries where each dictionary represents an event. An event dictionary contains properties describing that event.

Example:

curl http://127.0.0.1:8888/Test_Cluster/events?count=1

Output:

{
  "action": 28,
  "api_source_ip": 192.168.1.12,
  "event_source": "OpsCenter",
  "level": 1,
  "level_str": "INFO",
  "message": "Restarting node 192.168.100.3",
  "source_node": 192.168.100.3,
  "success": null,
  "target_node": null,
  "time": "1334768517145625",
  "user": "name"
}

GET /{cluster_id}/alerts/fired

Get all alerts that have been triggered

Path arguments:

Returns a list of alerts that have been triggered. Each item in the list is a dictionary that describes the triggered alert.

Example:

curl http://127.0.0.1:8888/Test_Cluster/alerts/fired

Output:

[
  {
    "alert_rule_id": "ca4cf071-03bd-486a-a8be-428e6cd7218a",
    "current_value": 31676303.333333332,
    "first_fired": 1336669233,
    "node": "10.11.12.150"
  },
  {
    "alert_rule_id": "ca4cf071-03bd-486a-a8be-428e6cd7218a",
    "current_value": 28380117.5,
    "first_fired": 1336669233,
    "node": "10.11.12.152"
  }
]

Was this helpful?

Give Feedback

How can we improve the documentation?

© Copyright IBM Corporation 2026 | Privacy policy | Terms of use |  Manage Privacy Choices

Apache, Apache Cassandra, Cassandra, Apache Tomcat, Tomcat, Apache Lucene, Apache Solr, Apache Hadoop, Hadoop, Apache Pulsar, Pulsar, Apache Spark, Spark, Apache TinkerPop, TinkerPop, Apache Kafka and Kafka are either registered trademarks or trademarks of the Apache Software Foundation or its subsidiaries in Canada, the United States and/or other countries. Kubernetes is the registered trademark of the Linux Foundation.

General Inquiries: Contact IBM