
# 创建告警规则 - CreateAlertRule
#### 功能介绍
创建告警规则
#### 调用方法
请参见[如何调用API](https://support.huaweicloud.com/api-secmaster/secmaster_03_0008.html)。
#### 授权信息
账号具备所有API的调用权限，如果使用账号下的IAM用户调用当前API，该IAM用户需具备调用API所需的权限，具体权限要求请参见[权限和授权项](https://support.huaweicloud.com/api-secmaster/secmaster_03_0023.html)。
#### URI
POST /v1/{project_id}/workspaces/{workspace_id}/siem/alert-rules
表1路径参数 
| 参数           | 是否必选 | 参数类型   | 描述      |
|:---|:---|:---|:---|
| project_id   | 是    | String | 项目 ID   |
| workspace_id | 是    | String | 工作空间 ID |
   
#### 请求参数
表2请求Header参数 
| 参数           | 是否必选 | 参数类型   | 描述                             |
|:---|:---|:---|:---|
| X-Auth-Token | 是    | String | 用户Token，通过调用IAM服务获取用户Token接口获取 |
   
表3请求Body参数 
| 参数                | 是否必选 | 参数类型                                                                            | 描述                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
|:---|:---|:---|:---|
| accumulated_times | 否    | Integer                                                                         | 执行次数                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| alert_description | 否    | String                                                                          | 告警描述                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| alert_name        | 是    | String                                                                          | 告警名称                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| alert_remediation | 否    | String                                                                          | 修复建议                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| alert_type        | 否    | Map\<String,String\>                                                            | 告警类型，通过"查询数据类列表" 接口获取.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| custom_properties | 否    | Map\<String,String\>                                                            | 自定义扩展信息                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| description       | 否    | String                                                                          | 描述                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| event_grouping    | 否    | Boolean                                                                         | 告警分组                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| pipe_id           | 是    | String                                                                          | 数据管道 ID                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| pipe_name         | 是    | String                                                                          | 管道名称                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| query             | 是    | String                                                                          | 查询语句                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| query_type        | 否    | String                                                                          | **参数解释**: 查询语法类型 - SQL查询   - SQL    **约束限制**: 不涉及 **取值范围**: **默认值**: SQL                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| rule_name         | 是    | String                                                                          | 告警规则名称                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| schedule          | 是    | [Schedule] object                           | 告警规则的调度周期                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| severity          | 否    | String                                                                          | **参数解释**: 告警等级 - TIPS 提示   - LOW 低危   - MEDIUM 中危   - HIGH 高危   - FATAL 致命    **约束限制** 不涉及 **取值范围**: - TIPS   - LOW   - MEDIUM   - HIGH   - FATAL    **默认值** 不涉及 |
| simulation        | 否    | Boolean                                                                         | 模拟告警                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| status            | 否    | String                                                                          | **参数解释**: 状态 - ENABLED 启用   - DISABLED 禁用    **约束限制** 不涉及 **取值范围**: - ENABLED   - DISABLED    **默认值** 不涉及                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| suppression       | 否    | Boolean                                                                         | 告警抑制                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| triggers          | 是    | Array of [AlertRuleTrigger] objects | 告警触发规则                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| label             | 否    | String                                                                          | 告警标签                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
   
 表4Schedule 
| 参数                 | 是否必选 | 参数类型    | 描述                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
|:---|:---|:---|:---|
| delay_interval     | 否    | Integer | 延迟间隔                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| frequency_interval | 是    | Integer | 调度间隔                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| frequency_unit     | 是    | String  | **参数解释**: 调度间隔单位 - MINUTE10 10分钟   - HOUR 小时   - DAY 天    **约束限制** 不涉及 **取值范围**: - MINUTE   - HOUR   - DAY    **默认值** 不涉及 |
| overtime_interval  | 否    | Integer | 超时间隔                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| period_interval    | 是    | Integer | 时间窗口间隔                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| period_unit        | 是    | String  | **参数解释**: 时间窗口单位 - MINUTE10 10分钟   - HOUR 小时   - DAY 天    **约束限制** 不涉及 **取值范围**: - MINUTE   - HOUR   - DAY    **默认值** 不涉及 |
   
 表5AlertRuleTrigger 
| 参数                | 是否必选 | 参数类型    | 描述                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
|:---|:---|:---|:---|
| accumulated_times | 否    | Integer | 累计次数                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| expression        | 是    | String  | 表达式                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| mode              | 否    | String  | **参数解释**: 指标模式 - COUNT 数量    **约束限制** 不涉及 **取值范围**: - COUNT    **默认值** 不涉及                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| operator          | 否    | String  | **参数解释**: 操作符类型 - GT 大于   - LT 小于   - EQ 等于   - NE 不等于    **约束限制** 不涉及 **取值范围**: - GT   - LT   - EQ   - NE    **默认值** 不涉及                                                                                                                                                                                                                                                                                              |
| severity          | 否    | String  | **参数解释**: 告警等级 - TIPS 提示   - LOW 低危   - MEDIUM 中危   - HIGH 高危   - FATAL 致命    **约束限制** 不涉及 **取值范围**: - TIPS   - LOW   - MEDIUM   - HIGH   - FATAL    **默认值** 不涉及 |
   
#### 响应参数
**状态码：200**
表6响应Header参数 
| 参数           | 参数类型   | 描述       |
|:---|:---|:---|
| X-request-id | String | 任务追踪请求ID |
   
表7响应Body参数 
| 参数                | 参数类型                                                                             | 描述                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
|:---|:---|:---|
| create_by         | String                                                                           | 创建人                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| create_time       | Long                                                                             | 创建时间                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| custom_properties | Map\<String,String\>                                                             | 自定义扩展信息                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| delete_time       | Long                                                                             | 删除时间                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| event_grouping    | Boolean                                                                          | 告警分组                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| pipe_id           | String                                                                           | 数据管道 ID                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| pipe_name         | String                                                                           | 数据管道名称                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| query             | String                                                                           | 查询语句                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| query_type        | String                                                                           | **参数解释**: 查询语法类型 - SQL查询   - SQL    **约束限制**: 不涉及 **取值范围**: **默认值**: SQL                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| rule_id           | String                                                                           | 告警规则 ID                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| rule_name         | String                                                                           | 告警规则名称                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| schedule          | [Schedule] object                           | 调度规则                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| severity          | String                                                                           | **参数解释**: 状态 - TIPS 提示   - LOW 低危   - MEDIUM 中危   - HIGH 高危   - FATAL 致命   - TIPS   - LOW   - MEDIUM   - HIGH   - FATAL    **约束限制** 不涉及 **取值范围**: **默认值** MEDIUM |
| status            | String                                                                           | **参数解释**: 状态 - ENABLED 启用   - DISABLED 禁用    **约束限制** 不涉及 **取值范围**: - ENABLED   - DISABLED    **默认值** 不涉及                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| triggers          | Array of [AlertRuleTrigger] objects | 告警触发规则                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| update_by         | String                                                                           | 更新人                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| update_time       | Long                                                                             | 更新时间                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| label             | String                                                                           | 告警标签                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
   
 表8Schedule 
| 参数                 | 参数类型    | 描述                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
|:---|:---|:---|
| delay_interval     | Integer | 延迟间隔                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| frequency_interval | Integer | 调度间隔                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| frequency_unit     | String  | **参数解释**: 调度间隔单位 - MINUTE10 10分钟   - HOUR 小时   - DAY 天    **约束限制** 不涉及 **取值范围**: - MINUTE   - HOUR   - DAY    **默认值** 不涉及 |
| overtime_interval  | Integer | 超时间隔                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| period_interval    | Integer | 时间窗口间隔                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| period_unit        | String  | **参数解释**: 时间窗口单位 - MINUTE10 10分钟   - HOUR 小时   - DAY 天    **约束限制** 不涉及 **取值范围**: - MINUTE   - HOUR   - DAY    **默认值** 不涉及 |
   
 表9AlertRuleTrigger 
| 参数                | 参数类型    | 描述                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
|:---|:---|:---|
| accumulated_times | Integer | 累计次数                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| expression        | String  | 表达式                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| mode              | String  | **参数解释**: 指标模式 - COUNT 数量    **约束限制** 不涉及 **取值范围**: - COUNT    **默认值** 不涉及                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| operator          | String  | **参数解释**: 操作符类型 - GT 大于   - LT 小于   - EQ 等于   - NE 不等于    **约束限制** 不涉及 **取值范围**: - GT   - LT   - EQ   - NE    **默认值** 不涉及                                                                                                                                                                                                                                                                                              |
| severity          | String  | **参数解释**: 告警等级 - TIPS 提示   - LOW 低危   - MEDIUM 中危   - HIGH 高危   - FATAL 致命    **约束限制** 不涉及 **取值范围**: - TIPS   - LOW   - MEDIUM   - HIGH   - FATAL    **默认值** 不涉及 |
   
**状态码：400**
表10响应Header参数 
| 参数           | 参数类型   | 描述       |
|:---|:---|:---|
| X-request-id | String | 任务追踪请求ID |
   
#### 请求示例
创建一条告警规则，告警规则所属的管道ID为772fb35b-83bc-46c9-a0b1-ebe31070a889，告警规则名称为Alert rule，查询类型为SQL，状态为启用。
```
{
  "accumulated_times" : 1,
  "alert_name" : "test",
  "custom_properties" : {
    "maintainer" : "isap",
    "references" : "https://localhost/references"
  },
  "description" : "An alert rule",
  "event_grouping" : false,
  "pipe_id" : "772fb35b-83bc-46c9-a0b1-ebe31070a889",
  "pipe_name" : "sec-hss-alarm",
  "query" : "* | select status, count(*) as count group by status",
  "query_type" : "SQL",
  "rule_name" : "Alert rule",
  "schedule" : {
    "delay_interval" : 2,
    "frequency_interval" : 5,
    "frequency_unit" : "MINUTE",
    "overtime_interval" : 10,
    "period_interval" : 5,
    "period_unit" : "MINUTE"
  },
  "severity" : "TIPS",
  "simulation" : false,
  "status" : "ENABLED",
  "suppression" : false,
  "triggers" : [ {
    "accumulated_times" : 1,
    "expression" : 10,
    "mode" : "COUNT",
    "operator" : "GT",
    "severity" : "TIPS"
  } ]
}
```
#### 响应示例
**状态码：200**
请求成功
```
{
  "create_by" : "582dd19dd99d4505a1d7929dc943b169",
  "create_time" : 1665221214,
  "custom_properties" : {
    "maintainer" : "isap",
    "references" : "https://localhost/references"
  },
  "delete_time" : 0,
  "event_grouping" : true,
  "pipe_id" : "772fb35b-83bc-46c9-a0b1-ebe31070a889",
  "query" : "* | select status, count(*) as count group by status",
  "query_type" : "SQL",
  "rule_id" : "443a0117-1aa4-4595-ad4a-796fad4d4950",
  "rule_name" : "Alert rule",
  "schedule" : {
    "delay_interval" : 2,
    "frequency_interval" : 5,
    "frequency_unit" : "MINUTE",
    "overtime_interval" : 10,
    "period_interval" : 5,
    "period_unit" : "MINUTE"
  },
  "severity" : "TIPS",
  "status" : "ENABLED",
  "triggers" : [ {
    "expression" : 10,
    "mode" : "COUNT",
    "operator" : "GT",
    "severity" : "TIPS"
  } ],
  "update_by" : "582dd19dd99d4505a1d7929dc943b169",
  "update_time" : 1665221214
}
```
#### SDK代码示例
SDK代码示例如下。
- [Java]
  创建一条告警规则，告警规则所属的管道ID为772fb35b-83bc-46c9-a0b1-ebe31070a889，告警规则名称为Alert rule，查询类型为SQL，状态为启用。
  ```
  package com.huaweicloud.sdk.test;
  import com.huaweicloud.sdk.core.auth.ICredential;
  import com.huaweicloud.sdk.core.auth.BasicCredentials;
  import com.huaweicloud.sdk.core.exception.ConnectionException;
  import com.huaweicloud.sdk.core.exception.RequestTimeoutException;
  import com.huaweicloud.sdk.core.exception.ServiceResponseException;
  import com.huaweicloud.sdk.secmaster.v1.region.SecMasterRegion;
  import com.huaweicloud.sdk.secmaster.v1.*;
  import com.huaweicloud.sdk.secmaster.v1.model.*;
  import java.util.List;
  import java.util.ArrayList;
  import java.util.Map;
  import java.util.HashMap;
  public class CreateAlertRuleSolution {
      public static void main(String[] args) {
          // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
          // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
          String ak = System.getenv("CLOUD_SDK_AK");
          String sk = System.getenv("CLOUD_SDK_SK");
          String projectId = "{project_id}";
          ICredential auth = new BasicCredentials()
                  .withProjectId(projectId)
                  .withAk(ak)
                  .withSk(sk);
          SecMasterClient client = SecMasterClient.newBuilder()
                  .withCredential(auth)
                  .withRegion(SecMasterRegion.valueOf("<YOUR REGION>"))
                  .build();
          CreateAlertRuleRequest request = new CreateAlertRuleRequest();
          request.withWorkspaceId("{workspace_id}");
          CreateAlertRuleRequestBody body = new CreateAlertRuleRequestBody();
          List<AlertRuleTrigger> listbodyTriggers = new ArrayList<>();
          listbodyTriggers.add(
              new AlertRuleTrigger()
                  .withAccumulatedTimes(1)
                  .withExpression("10")
                  .withMode(AlertRuleTrigger.ModeEnum.fromValue("COUNT"))
                  .withOperator(AlertRuleTrigger.OperatorEnum.fromValue("GT"))
                  .withSeverity(AlertRuleTrigger.SeverityEnum.fromValue("TIPS"))
          );
          Schedule schedulebody = new Schedule();
          schedulebody.withDelayInterval(2)
              .withFrequencyInterval(5)
              .withFrequencyUnit(Schedule.FrequencyUnitEnum.fromValue("MINUTE"))
              .withOvertimeInterval(10)
              .withPeriodInterval(5)
              .withPeriodUnit(Schedule.PeriodUnitEnum.fromValue("MINUTE"));
          Map<String, String> listbodyCustomProperties = new HashMap<>();
          listbodyCustomProperties.put("maintainer", "isap");
          listbodyCustomProperties.put("references", "https://localhost/references");
          body.withTriggers(listbodyTriggers);
          body.withSuppression(false);
          body.withStatus(CreateAlertRuleRequestBody.StatusEnum.fromValue("ENABLED"));
          body.withSimulation(false);
          body.withSeverity(CreateAlertRuleRequestBody.SeverityEnum.fromValue("TIPS"));
          body.withSchedule(schedulebody);
          body.withRuleName("Alert rule");
          body.withQueryType(CreateAlertRuleRequestBody.QueryTypeEnum.fromValue("SQL"));
          body.withQuery("* | select status, count(*) as count group by status");
          body.withPipeName("sec-hss-alarm");
          body.withPipeId("772fb35b-83bc-46c9-a0b1-ebe31070a889");
          body.withEventGrouping(false);
          body.withDescription("An alert rule");
          body.withCustomProperties(listbodyCustomProperties);
          body.withAlertName("test");
          body.withAccumulatedTimes(1);
          request.withBody(body);
          try {
              CreateAlertRuleResponse response = client.createAlertRule(request);
              System.out.println(response.toString());
          } catch (ConnectionException e) {
              e.printStackTrace();
          } catch (RequestTimeoutException e) {
              e.printStackTrace();
          } catch (ServiceResponseException e) {
              e.printStackTrace();
              System.out.println(e.getHttpStatusCode());
              System.out.println(e.getRequestId());
              System.out.println(e.getErrorCode());
              System.out.println(e.getErrorMsg());
          }
      }
  }
  ```
- [Python]
  创建一条告警规则，告警规则所属的管道ID为772fb35b-83bc-46c9-a0b1-ebe31070a889，告警规则名称为Alert rule，查询类型为SQL，状态为启用。
  ```
  # coding: utf-8
  import os
  from huaweicloudsdkcore.auth.credentials import BasicCredentials
  from huaweicloudsdksecmaster.v1.region.secmaster_region import SecMasterRegion
  from huaweicloudsdkcore.exceptions import exceptions
  from huaweicloudsdksecmaster.v1 import *
  if __name__ == "__main__":
      # The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
      # In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
      ak = os.environ["CLOUD_SDK_AK"]
      sk = os.environ["CLOUD_SDK_SK"]
      projectId = "{project_id}"
      credentials = BasicCredentials(ak, sk, projectId)
      client = SecMasterClient.new_builder() \
          .with_credentials(credentials) \
          .with_region(SecMasterRegion.value_of("<YOUR REGION>")) \
          .build()
      try:
          request = CreateAlertRuleRequest()
          request.workspace_id = "{workspace_id}"
          listTriggersbody = [
              AlertRuleTrigger(
                  accumulated_times=1,
                  expression="10",
                  mode="COUNT",
                  operator="GT",
                  severity="TIPS"
              )
          ]
          schedulebody = Schedule(
              delay_interval=2,
              frequency_interval=5,
              frequency_unit="MINUTE",
              overtime_interval=10,
              period_interval=5,
              period_unit="MINUTE"
          )
          listCustomPropertiesbody = {
              "maintainer": "isap",
              "references": "https://localhost/references"
          }
          request.body = CreateAlertRuleRequestBody(
              triggers=listTriggersbody,
              suppression=False,
              status="ENABLED",
              simulation=False,
              severity="TIPS",
              schedule=schedulebody,
              rule_name="Alert rule",
              query_type="SQL",
              query="* | select status, count(*) as count group by status",
              pipe_name="sec-hss-alarm",
              pipe_id="772fb35b-83bc-46c9-a0b1-ebe31070a889",
              event_grouping=False,
              description="An alert rule",
              custom_properties=listCustomPropertiesbody,
              alert_name="test",
              accumulated_times=1
          )
          response = client.create_alert_rule(request)
          print(response)
      except exceptions.ClientRequestException as e:
          print(e.status_code)
          print(e.request_id)
          print(e.error_code)
          print(e.error_msg)
  ```
- [Go]
  创建一条告警规则，告警规则所属的管道ID为772fb35b-83bc-46c9-a0b1-ebe31070a889，告警规则名称为Alert rule，查询类型为SQL，状态为启用。
  ```
  package main
  import (
  "fmt"
  "github.com/huaweicloud/huaweicloud-sdk-go-v3/core/auth/basic"
      secmaster "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/secmaster/v1"
  "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/secmaster/v1/model"
      region "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/secmaster/v1/region"
  )
  func main() {
      // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
      // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
      ak := os.Getenv("CLOUD_SDK_AK")
      sk := os.Getenv("CLOUD_SDK_SK")
      projectId := "{project_id}"
      auth, err := basic.NewCredentialsBuilder().
          WithAk(ak).
          WithSk(sk).
          WithProjectId(projectId).
          SafeBuild()
      if err != nil {
          fmt.Println(err)
          return
      }
      hcClient, err := secmaster.SecMasterClientBuilder().
           WithRegion(region.ValueOf("<YOUR REGION>")).
           WithCredential(auth).
           SafeBuild()
      if err != nil {
          fmt.Println(err)
          return
      }
      client := secmaster.NewSecMasterClient(hcClient)
      request := &model.CreateAlertRuleRequest{}
  request.WorkspaceId = "{workspace_id}"
  accumulatedTimesTriggers:= int32(1)
  modeTriggers:= model.GetAlertRuleTriggerModeEnum().COUNT
  operatorTriggers:= model.GetAlertRuleTriggerOperatorEnum().GT
  severityTriggers:= model.GetAlertRuleTriggerSeverityEnum().TIPS
  var listTriggersbody = []model.AlertRuleTrigger{
          {
              AccumulatedTimes: &accumulatedTimesTriggers,
              Expression: "10",
              Mode: &modeTriggers,
              Operator: &operatorTriggers,
              Severity: &severityTriggers,
          },
      }
  delayIntervalSchedule:= int32(2)
  overtimeIntervalSchedule:= int32(10)
  schedulebody := &model.Schedule{
  DelayInterval: &delayIntervalSchedule,
  FrequencyInterval: int32(5),
  FrequencyUnit: model.GetScheduleFrequencyUnitEnum().MINUTE,
  OvertimeInterval: &overtimeIntervalSchedule,
  PeriodInterval: int32(5),
  PeriodUnit: model.GetSchedulePeriodUnitEnum().MINUTE,
  }
  var listCustomPropertiesbody = map[string]string{
          "maintainer": "isap",
          "references": "https://localhost/references",
      }
  suppressionCreateAlertRuleRequestBody:= false
  statusCreateAlertRuleRequestBody:= model.GetCreateAlertRuleRequestBodyStatusEnum().ENABLED
  simulationCreateAlertRuleRequestBody:= false
  severityCreateAlertRuleRequestBody:= model.GetCreateAlertRuleRequestBodySeverityEnum().TIPS
  queryTypeCreateAlertRuleRequestBody:= model.GetCreateAlertRuleRequestBodyQueryTypeEnum().SQL
  eventGroupingCreateAlertRuleRequestBody:= false
  descriptionCreateAlertRuleRequestBody:= "An alert rule"
  accumulatedTimesCreateAlertRuleRequestBody:= int32(1)
  request.Body = &model.CreateAlertRuleRequestBody{
  Triggers: listTriggersbody,
  Suppression: &suppressionCreateAlertRuleRequestBody,
  Status: &statusCreateAlertRuleRequestBody,
  Simulation: &simulationCreateAlertRuleRequestBody,
  Severity: &severityCreateAlertRuleRequestBody,
  Schedule: schedulebody,
  RuleName: "Alert rule",
  QueryType: &queryTypeCreateAlertRuleRequestBody,
  Query: "* | select status, count(*) as count group by status",
  PipeName: "sec-hss-alarm",
  PipeId: "772fb35b-83bc-46c9-a0b1-ebe31070a889",
  EventGrouping: &eventGroupingCreateAlertRuleRequestBody,
  Description: &descriptionCreateAlertRuleRequestBody,
  CustomProperties: listCustomPropertiesbody,
  AlertName: "test",
  AccumulatedTimes: &accumulatedTimesCreateAlertRuleRequestBody,
  }
  response, err := client.CreateAlertRule(request)
  if err == nil {
          fmt.Printf("%+v\n", response)
      } else {
          fmt.Println(err)
      }
  }
  ```
- [更多]
  更多编程语言的SDK代码示例，请参见[API Explorer](https://console.huaweicloud.com/apiexplorer/#/openapi/SecMaster/sdk?api=CreateAlertRule&version=v1)的代码示例页签，可生成自动对应的SDK代码示例。
#### 状态码
| 状态码 | 描述   |
|:---|:---|
| 200 | 请求成功 |
| 400 | 请求失败 |
   
#### 错误码
请参见[错误码](https://support.huaweicloud.com/api-secmaster/ErrorCode.html)。
