> ## Documentation Index
> Fetch the complete documentation index at: https://test-8ad8522e-feat-ai-sre.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# 导出告警规则

> 将选定告警规则的配置导出为可移植的 JSON 数组，与 `POST /monit/rule/import` 兼容。

## 限制说明

| 项目   | 说明                                         |
| ---- | ------------------------------------------ |
| 速率限制 | 每个账户 **1,000 次/天**；**200 次/分钟**；**20 次/秒** |
| 权限要求 | **告警规则查看**（`monit`）                        |


## OpenAPI

````yaml /api-reference/monitors.openapi.zh.json post /monit/rule/export
openapi: 3.1.0
info:
  title: Flashduty 开放 API
  description: >-
    Flashduty 事件管理平台的公开 HTTP API —— 覆盖故障、通知模板、协作空间、值班排班、监控、RUM、以及平台管理。每次调用都需在
    query 中携带 `app_key`，该 key 在 Flashduty 控制台 账户 → APP Key 中签发。所有响应使用统一结构：成功时为
    `{ request_id, data }`，失败时为 `{ request_id, error }`。
  version: 1.0.0
servers:
  - url: https://api.flashcat.cloud
    description: Flashduty Open API
security:
  - AppKeyAuth: []
tags:
  - name: Monitors/告警规则
    description: 创建、管理和导出监控告警规则，查询规则统计和审计历史。
  - name: Monitors/告警数据源
    description: 管理监控告警规则用于查询指标的数据源。
  - name: Monitors/诊断分析
    description: Flashduty AI SRE 使用的诊断与查询接口——数据源即席查询、日志/指标诊断,以及监控对象侧的工具调用。
  - name: Monitors/通用工具
    description: 监控服务开通及数据预览工具。
paths:
  /monit/rule/export:
    post:
      tags:
        - Monitors/告警规则
      summary: 导出告警规则
      description: 将选定告警规则的配置导出为可移植的 JSON 数组，与 `POST /monit/rule/import` 兼容。
      operationId: monit-rule-read-export
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RuleIDsRequest'
            example:
              ids:
                - 50001
      responses:
        '200':
          description: 成功
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/SuccessEnvelope'
                  - type: object
                    properties:
                      data:
                        $ref: '#/components/schemas/AlertRuleExportListResponse'
              example:
                request_id: 01HK8XQE3Z7JM2NTFQ5YJ8P9R4
                data:
                  - name: CPU High
                    ds_type: prometheus
                    ds_list:
                      - prometheus*
                    enabled: true
                    cron_pattern: 0 * * * * *
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '429':
          $ref: '#/components/responses/TooManyRequests'
        '500':
          $ref: '#/components/responses/ServerError'
components:
  schemas:
    RuleIDsRequest:
      type: object
      required:
        - ids
      properties:
        ids:
          type: array
          items:
            type: integer
            format: uint64
          description: 规则 ID 列表。
    SuccessEnvelope:
      type: object
      description: >-
        成功响应结构。2xx 响应中 `request_id` 标识本次调用（同时出现在 `Flashcat-Request-Id`
        响应头中），`data` 为接口业务 payload。失败响应使用不同结构，参见 `ErrorResponse`。
      properties:
        request_id:
          type: string
          description: 本次请求的唯一 ID，也会在 Flashcat-Request-Id 响应头中返回。反馈问题时请一并附上。
          example: 01HK8XQE3Z7JM2NTFQ5YJ8P9R4
        data:
          description: 每个接口自己的业务 payload，详见各接口的 200 响应 schema。
      required:
        - request_id
        - data
    AlertRuleExportListResponse:
      type: array
      description: 导出的规则配置列表，兼容 `POST /monit/rule/import`。
      items:
        $ref: '#/components/schemas/AlertRuleExport'
    AlertRuleExport:
      type: object
      description: 用于导入/导出的便携告警规则表示，省略 `id`、`account_id` 等标识字段与审计元数据。
      required:
        - name
        - ds_type
        - enabled
        - debug_log_enabled
        - cron_pattern
      properties:
        name:
          type: string
          description: 规则名称，导入账户内最长 128 字符。
        labels:
          type: object
          additionalProperties:
            type: string
          description: 自定义标签键值对，会附加到该规则产生的告警事件上。
        ds_type:
          type: string
          description: 数据源类型标识，如 `prometheus`；须为导入环境中已存在的数据源类型（`ident`）。
        ds_list:
          type: array
          items:
            type: string
          description: 数据源名称列表，支持通配符；与 `ds_ids` 合并后共同决定规则监控哪些数据源，数据源改名后需手工维护。
        ds_ids:
          type: array
          items:
            type: integer
            format: uint64
          description: 数据源 ID 列表，与 `ds_list` 合并生效；按 ID 引用，不受数据源改名影响。
        enabled:
          type: boolean
          description: 规则是否启用；导入为禁用的规则不参与评估。
        debug_log_enabled:
          type: boolean
          description: 是否输出该规则评估过程的调试日志，排障时开启。
        rule_configs:
          $ref: '#/components/schemas/RuleConfigs'
        cron_pattern:
          type: string
          description: >-
            评估调度，支持 6 字段（含秒）cron 表达式或 `@every <duration>`（时长须为整秒且不小于 1s）；不允许
            `CRON_TZ=`/`TZ=` 前缀，时区写在 `timezone`。
        timezone:
          type: string
          description: 告警规则执行时区，IANA 时区名，默认 `Asia/Shanghai`。
          default: Asia/Shanghai
        delay_seconds:
          type: integer
          description: 查询时间偏移（秒）：每次评估按「调度时刻 − delay_seconds」取数，规避数据采集/入库延迟；`0` 表示不偏移。
        enabled_times:
          type: array
          items:
            $ref: '#/components/schemas/EnabledTime'
          description: >-
            生效时间窗口列表；每项含 `days`（0–6，0 表示周日）、`stime`/`etime`（`HH:MM`），窗口按规则
            `timezone` 解释，空列表表示不生效。
        annotations:
          type: object
          additionalProperties:
            type: string
          description: 附加到告警事件的自定义注解键值对；键不允许以 `$` 开头（`$` 前缀保留给查询字段引用）。
        description_type:
          type: string
          enum:
            - text
            - markdown
          description: '`description` 的格式，`text` 或 `markdown`；省略时按 `text` 处理。'
        description:
          type: string
          description: 规则说明，格式由 `description_type` 指定，会随告警事件展示。
        repeat_interval:
          type: integer
          format: int64
          description: 告警重复通知间隔（秒）；小于 1 时按默认值 3600 处理。
        repeat_total:
          type: integer
          format: int64
          description: 同一告警的最大重复通知次数；小于 1 时按默认值 3 处理。
    ErrorResponse:
      type: object
      description: 错误响应结构。`error` 必填，`data` 不存在。
      properties:
        request_id:
          type: string
          example: 01HK8XQE3Z7JM2NTFQ5YJ8P9R4
          description: 本次请求的唯一追踪 ID（trace ID），反馈问题时请提供该值以便检索日志。
        error:
          $ref: '#/components/schemas/DutyError'
      required:
        - request_id
        - error
    RuleConfigs:
      type: object
      description: 规则评估配置。
      properties:
        queries:
          type: array
          items:
            type: object
            properties:
              name:
                type: string
                description: 查询标识符（字母，如 `A`）。`R` 为保留名称，不可使用。
              expr:
                type: string
                description: 查询表达式。
              label_fields:
                type: array
                items:
                  type: string
                description: >-
                  作为告警事件标签的结果字段列表，相同标签组合归为同一告警；不可与 `value_fields`
                  重复，适用于表型结果（SQL/ES 等数据源）。
              value_fields:
                type: array
                items:
                  type: string
                description: >-
                  参与阈值评估的数值结果字段列表（以 `$A.<field>` 形式被阈值表达式引用）；对阈值检查且数据源非
                  `prometheus`/`loki`/`victorialogs` 时必填，字段名不允许含 `.`。
              args:
                type: object
                additionalProperties:
                  type: string
                description: >-
                  数据源相关的查询附加参数，键采用 `<数据源>.<参数>` 约定（如
                  `es.type`、`tencent_cls.limit`）；大多数数据源无需配置。
          description: 查询列表，至少一条；每条需唯一的 `name`（`R`、`__all__` 为保留名）与非空且不重复的 `expr`。
        relate_queries:
          type: array
          description: 可选的辅助查询，其结果作为上下文附加到告警事件中。每项须有唯一的 `name`（不与任何 query 名称重复）且 `expr` 非空。
          items:
            type: object
            properties:
              name:
                type: string
                description: 辅助查询标识符。
              expr:
                type: string
                description: 查询表达式。
              args:
                type: object
                additionalProperties:
                  type: string
                description: 辅助查询的数据源相关附加参数，约定同 `queries[].args`。
        check_threshold:
          type: object
          description: 阈值检查配置。
          properties:
            enabled:
              type: boolean
              description: 是否启用阈值检查。
            alerting_check_times:
              type: integer
              description: 连续满足告警条件多少次后触发告警，最小为 1。
            recovery_check_times:
              type: integer
              description: 连续满足恢复条件多少次后判定恢复，最小为 1。
            push_recovery_event:
              type: boolean
              description: 告警恢复时是否推送恢复事件通知。
            critical:
              type: string
              description: >-
                Critical 级别阈值表达式，用 `$<查询名>` 或 `$<查询名>.<value_field>` 引用查询结果，如
                `$A > 90`；三个级别至少配置一个。
            warning:
              type: string
              description: Warning 级别阈值表达式，语法同 `critical`。
            info:
              type: string
              description: Info 级别阈值表达式，语法同 `critical`。
            recovery:
              type: object
              properties:
                mode:
                  type: string
                  enum:
                    - invert
                    - threshold
                    - ql
                  description: >-
                    恢复判定方式：`invert` = 告警表达式不再成立即恢复（此时 `condition`
                    为空）；`threshold` = `condition` 阈值表达式成立时恢复；`ql` = `condition`
                    查询表达式为真时恢复。
                condition:
                  type: string
                  description: 恢复条件表达式；`mode` 为 `threshold` 或 `ql` 时必填，`invert` 时必须为空。
                value_fields:
                  type: array
                  items:
                    type: string
                  description: >-
                    恢复条件 `condition` 以 `$A.<field>` 形式引用的数值结果字段，语义同查询的
                    `value_fields`。为空时不返回。
                args:
                  type: object
                  additionalProperties:
                    type: string
                  description: 恢复查询的数据源附加参数，键约定同查询的 `args`（`<数据源>.<参数>`）。为空时不返回。
              description: 阈值检查的恢复判定配置。
        check_anydata:
          type: object
          description: 有数据检查配置。查询返回任意数据行时触发告警。
          properties:
            enabled:
              type: boolean
              description: 是否启用有数据检查：查询返回任意数据行即触发告警。
            alerting_check_times:
              type: integer
              description: 连续满足告警条件多少次后触发告警，最小为 1。
            recovery_check_times:
              type: integer
              description: 连续满足恢复条件多少次后判定恢复，最小为 1。
            push_recovery_event:
              type: boolean
              description: 告警恢复时是否推送恢复事件通知。
            severity:
              type: string
              enum:
                - Critical
                - Warning
                - Info
              description: 有数据告警的事件级别，大小写敏感。
            recovery:
              type: object
              description: 有数据检查的恢复条件。省略或 `mode` 为空时按 `nodata` 处理。
              properties:
                mode:
                  type: string
                  enum:
                    - nodata
                    - ql
                  description: >-
                    `nodata` = 查询无数据时恢复；`ql` = `condition` 表达式为真时恢复。`mode` 为
                    `ql` 时，仅允许单个查询（`name=A`）。
                condition:
                  type: string
                  description: 恢复表达式，`mode` 为 `ql` 时必填。
                args:
                  type: object
                  additionalProperties:
                    type: string
                  description: >-
                    恢复查询的数据源相关附加参数，约定同 `queries[].args`；Elasticsearch 数据源且
                    `mode` 为 `ql` 时需要配置。
        check_nodata:
          type: object
          description: 无数据检查配置。
          properties:
            enabled:
              type: boolean
              description: 是否启用无数据检查：历史上有数据的序列查不到数据时触发告警。
            alerting_check_times:
              type: integer
              description: 连续满足告警条件多少次后触发告警，最小为 1。
            recovery_check_times:
              type: integer
              description: 连续满足恢复条件多少次后判定恢复，最小为 1。
            push_recovery_event:
              type: boolean
              description: 告警恢复时是否推送恢复事件通知。
            severity:
              type: string
              enum:
                - Critical
                - Warning
                - Info
              description: 无数据告警的事件级别，大小写敏感。
            resolve_timeout:
              type: integer
              description: 自动恢复等待时间（秒）。
            alert_on_empty_result:
              type: boolean
              description: 所有查询都返回空结果时是否触发告警。
            alert_on_empty_result_severity:
              type: string
              enum:
                - Critical
                - Warning
                - Info
              description: 空结果告警的事件级别，大小写敏感；仅在 `alert_on_empty_result` 开启时生效。
      required:
        - queries
    EnabledTime:
      type: object
      description: 规则激活时间窗口。
      properties:
        days:
          type: array
          items:
            type: integer
          description: 星期几，0 = 周日。
        stime:
          type: string
          description: 起始时间，如 `09:00`。
        etime:
          type: string
          description: 结束时间，如 `18:00`。
    DutyError:
      type: object
      description: 响应结构中的错误 payload，仅在非 2xx 响应时出现。
      properties:
        code:
          $ref: '#/components/schemas/ErrorCode'
        message:
          type: string
          description: 用户可读的错误描述，语言会跟随调用方的 Accept-Language。可能包含字段名、ID 等请求上下文。
          example: The specified parameter template_id is not valid.
        reason:
          description: 可选的机器可读拒绝原因，包含数据源工具错误；结合 HTTP 状态及 code 判断。
          type: string
          x-flashduty-preserve-absence: true
      required:
        - code
        - message
    ErrorCode:
      type: string
      description: >-
        Flashduty 错误码枚举。每个失败响应的 `error.code` 都是下列稳定值之一，HTTP 状态码仅作参考。


        | 错误码 | HTTP | 含义 |

        |---|---|---|

        | `OK` | 200 | 保留值，正常错误响应不会返回。 |

        | `InvalidParameter` | 400 | 必填参数缺失或未通过校验。 |

        | `BadRequest` | 400 | 通用的 400 错误，通常是请求本身不合法。 |

        | `InvalidContentType` | 400 | 请求头 `Content-Type` 不是 `application/json`。
        |

        | `ResourceNotFound` | 400 | 目标资源不存在。注意 HTTP 状态码是 400 而非 404（历史设计）。 |

        | `NoLicense` | 400 | 功能需要有效授权，但未找到可用的 license。 |

        | `ReferenceExist` | 400 | 该资源仍被其他实体引用，无法删除。 |

        | `Unauthorized` | 401 | `app_key` 缺失、无效或已过期。 |

        | `BalanceNotEnough` | 402 | 账户余额不足，无法执行需要计费的操作。 |

        | `AccessDenied` | 403 | 身份认证通过，但 RBAC 权限不足以执行该操作。 |

        | `RouteNotFound` | 404 | 请求的 URL 路径不是已知路由。 |

        | `MethodNotAllowed` | 405 | 当前路径不接受所使用的 HTTP 方法。 |

        | `UndonedOrderExist` | 409 | 账户存在未完成的订单，请稍后重试。 |

        | `RequestLocked` | 423 | 因连续失败被临时锁定。 |

        | `EntityTooLarge` | 413 | 请求体超过允许的最大长度。 |

        | `RequestTooFrequently` | 429 | 命中限流（全局、账户级或集成级）。 |

        | `RequestVerifyRequired` | 428 | 操作需要二次验证码，但未提供。 |

        | `DangerousOperation` | 428 | 危险操作，需要进行 MFA 验证。 |

        | `InternalError` | 500 | 服务端未预期错误。反馈问题请附上 `request_id`。 |

        | `ServiceUnavailable` | 503 | 后端依赖不可用，请稍后重试。 |
      enum:
        - OK
        - InvalidParameter
        - BadRequest
        - InvalidContentType
        - ResourceNotFound
        - NoLicense
        - ReferenceExist
        - Unauthorized
        - BalanceNotEnough
        - AccessDenied
        - RouteNotFound
        - MethodNotAllowed
        - UndonedOrderExist
        - RequestLocked
        - EntityTooLarge
        - RequestTooFrequently
        - RequestVerifyRequired
        - DangerousOperation
        - InternalError
        - ServiceUnavailable
      x-enumDescriptions:
        OK: 保留值，正常错误响应不会返回。
        InvalidParameter: 必填参数缺失或未通过校验。
        BadRequest: 通用的 400 错误，通常是请求本身不合法。
        InvalidContentType: 请求头 `Content-Type` 不是 `application/json`。
        ResourceNotFound: 目标资源不存在。注意 HTTP 状态码是 400 而非 404（历史设计）。
        NoLicense: 功能需要有效授权，但未找到可用的 license。
        ReferenceExist: 该资源仍被其他实体引用，无法删除。
        Unauthorized: '`app_key` 缺失、无效或已过期。'
        BalanceNotEnough: 账户余额不足，无法执行需要计费的操作。
        AccessDenied: 身份认证通过，但 RBAC 权限不足以执行该操作。
        RouteNotFound: 请求的 URL 路径不是已知路由。
        MethodNotAllowed: 当前路径不接受所使用的 HTTP 方法。
        UndonedOrderExist: 账户存在未完成的订单，请稍后重试。
        RequestLocked: 因连续失败被临时锁定。
        EntityTooLarge: 请求体超过允许的最大长度。
        RequestTooFrequently: 命中限流（全局、账户级或集成级）。
        RequestVerifyRequired: 操作需要二次验证码，但未提供。
        DangerousOperation: 危险操作，需要进行 MFA 验证。
        InternalError: 服务端未预期错误。反馈问题请附上 `request_id`。
        ServiceUnavailable: 后端依赖不可用，请稍后重试。
      example: InvalidParameter
  responses:
    BadRequest:
      description: 请求非法 — 通常是参数缺失或格式不正确。
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            missingParameter:
              value:
                request_id: 01HK8XQE3Z7JM2NTFQ5YJ8P9R4
                error:
                  code: InvalidParameter
                  message: The specified parameter is not valid.
    Unauthorized:
      description: app_key 缺失或无效。
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            missingAppKey:
              value:
                request_id: 01HK8XQE3Z7JM2NTFQ5YJ8P9R4
                error:
                  code: Unauthorized
                  message: You are unauthorized.
    TooManyRequests:
      description: 命中限流。可能是全局 API 限流、账户级限流或集成级限流。限流按账户聚合。
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            rateLimited:
              value:
                request_id: 01HK8XQE3Z7JM2NTFQ5YJ8P9R4
                error:
                  code: RequestTooFrequently
                  message: Request too frequently.
    ServerError:
      description: 服务端未预期错误。反馈问题时请携带 request_id。
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            internal:
              value:
                request_id: 01HK8XQE3Z7JM2NTFQ5YJ8P9R4
                error:
                  code: InternalError
                  message: >-
                    We encountered an internal error, and it has been reported.
                    Please try again later.
  securitySchemes:
    AppKeyAuth:
      type: apiKey
      in: query
      name: app_key
      description: >-
        在 Flashduty 控制台 账户 → APP Key 中签发的 app_key。调用任何公开 API
        时都必须携带。它等同于所属账户的身份凭证，请妥善保管。

````