LitmusEdgeManager 2.31.x API Documentation/Admin Console APIs/Instance Alerts - LE, LEM, LUNS API Docs
Get Triggers
GET {{LEM_adminURL}}/admin/v1/instance-alert/trigger/definition?scopeType=USER
Get Triggers
Returns the instance-alert triggers, optionally filtered by scope type (USER / SYSTEM).
Endpoint
GET {{LEM_adminURL}}/admin/v1/instance-alert/trigger/definition?scopeType=USER
Authentication
HTTP Basic Auth. Username is your API token, password is empty. Tokens are managed under System > Access Control > Tokens.
Errors
| HTTP status | When it happens |
|---|---|
400 Bad Request |
Missing or malformed query/body parameter. |
401 Unauthorized |
Missing or invalid credentials. |
403 Forbidden |
Token lacks permission for this operation. |
404 Not Found |
Target entity does not exist. |
5xx |
Service is unreachable, restarting, or internally errored. Inspect device logs under System > Support. |
TLS note: edge devices use a self-signed certificate by default. Either install the device CA in your client trust store or disable certificate verification when calling this endpoint directly.
Response
Status: 200 OK
[
{
"id": "2clgjpc8tf2nogn5f2eks1mnv",
"name": "Trigger",
"description": "",
"simpleRules": null,
"eventRules": null,
"rawDataRules": null,
"metricRules": [
{
"templateCode": "DISK_SPACE_LOW",
"targetValue": "10"
}
],
"auditEventRules": [],
"advancedRules": null,
"deduplicate": false,
"severity": 0,
"subject": "Free disk space less than $targetValue%",
"message": "Free disk space $value% is less than $targetValue% on filesystem $mountpoint",
"messageResolved": "",
"tags": null,
"deviceId": null,
"actions": [],
"active": false,
"showOnDashboard": false,
"scopeType": "USER",
"sourceType": "METRICS",
"updatedOn": 1767978510587,
"notifyContinuously": false,
"notifyGracePeriod": 0,
"alertDelay": 60,
"scope": "INSTANCE"
}
]
Create/Update Trigger
POST {{LEM_adminURL}}/admin/v1/instance-alert/trigger/definition
Create / Update Trigger
Creates a new instance-alert trigger, or updates an existing one when id is supplied. Triggers can be metric-based (metricRules[]), event-based, or audit-event-based.
Endpoint
POST {{LEM_adminURL}}/admin/v1/instance-alert/trigger/definition
Authentication
HTTP Basic Auth. Username is your API token, password is empty. Tokens are managed under System > Access Control > Tokens.
Request body
{
"name": "Disk Space Low",
"subject": "Free disk space less than $targetValue%",
"message": "Free disk space $value% is less than $targetValue%",
"active": false,
"scope": "INSTANCE",
"scopeType": "USER",
"sourceType": "METRICS",
"severity": 0,
"actions": [],
"metricRules": [{ "templateCode": "DISK_SPACE_LOW", "targetValue": "10" }]
}
Errors
| HTTP status | When it happens |
|---|---|
400 Bad Request |
Missing or malformed query/body parameter. |
401 Unauthorized |
Missing or invalid credentials. |
403 Forbidden |
Token lacks permission for this operation. |
404 Not Found |
Target entity does not exist. |
5xx |
Service is unreachable, restarting, or internally errored. Inspect device logs under System > Support. |
TLS note: edge devices use a self-signed certificate by default. Either install the device CA in your client trust store or disable certificate verification when calling this endpoint directly.
Request Body
{
"name": "Disk Space Low",
"description": "",
"subject": "Free disk space less than $targetValue%",
"message": "Free disk space $value% is less than $targetValue% on filesystem $mountpoint",
"messageResolved": "",
"active": false,
"scope": "INSTANCE",
"scopeType": "USER",
"sourceType": "METRICS",
"notifyContinuously": false,
"notifyGracePeriod": 0,
"severity": 0,
"actions": [],
"auditEventRules": [],
"metricRules": [
{
"templateCode": "DISK_SPACE_LOW",
"targetValue": 10
}
],
"alertDelay": 60
}
Response
Status: 200 OK
{
"id": "f27z42mvw79wgdkyi1a8qeocb",
"name": "Disk Space Low",
"description": "",
"simpleRules": null,
"eventRules": null,
"rawDataRules": null,
"metricRules": [
{
"templateCode": "DISK_SPACE_LOW",
"targetValue": "10"
}
],
"auditEventRules": [],
"advancedRules": null,
"deduplicate": false,
"severity": 0,
"subject": "Free disk space less than $targetValue%",
"message": "Free disk space $value% is less than $targetValue% on filesystem $mountpoint",
"messageResolved": "",
"tags": null,
"deviceId": null,
"actions": [],
"active": false,
"showOnDashboard": false,
"scopeType": "USER",
"sourceType": "METRICS",
"updatedOn": 1767978623913,
"notifyContinuously": false,
"notifyGracePeriod": 0,
"alertDelay": 60,
"scope": "INSTANCE"
}
Get Instance Trigger Templates
GET {{LEM_adminURL}}/admin/v1/instance-alert/trigger/templates
Get Instance Trigger Templates
Returns the pre-built instance-trigger templates (e.g. DISK_SPACE_LOW, CONNECTOR_DISK_BUFFER) with descriptions and message templates. Use to populate a trigger-creation UI.
Endpoint
GET {{LEM_adminURL}}/admin/v1/instance-alert/trigger/templates
Authentication
HTTP Basic Auth. Username is your API token, password is empty. Tokens are managed under System > Access Control > Tokens.
Errors
| HTTP status | When it happens |
|---|---|
400 Bad Request |
Missing or malformed query/body parameter. |
401 Unauthorized |
Missing or invalid credentials. |
403 Forbidden |
Token lacks permission for this operation. |
404 Not Found |
Target entity does not exist. |
5xx |
Service is unreachable, restarting, or internally errored. Inspect device logs under System > Support. |
TLS note: edge devices use a self-signed certificate by default. Either install the device CA in your client trust store or disable certificate verification when calling this endpoint directly.
Response
Status: 200 OK
[
{
"name": "Connector disk buffer",
"code": "CONNECTOR_DISK_BUFFER",
"message": "The usage of a CC disk buffer indicates that the connector's throughput is insufficient to handle all defined tags",
"summary": "The usage of CC $name disk buffer is above $targetValue MB more than $alertDelay seconds",
"description": "The usage of CC $name disk buffer $value is above $targetValue MB for Edge device $devicename",
"descriptionResolved": "The usage of CC $name disk buffer $value has returned to normal levels for Edge device $devicename",
"expression": "edge_cc_disk_usage{[[ $matchers ]]}*1048576 > [[ $targetValue ]]",
"group": "Integration",
"attributes": [
{
"name": "Target Value",
"code": "value",
"description": "Value of the disk buffer size to trigger an alert",
"datatype": "number",
"uom": "MB",
"type": "VALUE",
"values": [],
"defaultValue": 50
}
]
},
{
"name": "Connector online status",
"code": "CONNECTOR_ONLINE_STATUS",
"message": "Identify unplanned disconnections",
"summary": "CC connector $name is offline more than $alertDelay seconds",
"description": "CC connector $name is offline for Edge device $devicename",
"descriptionResolved": "CC connector $name is back online for Edge device $devicename",
"expression": "edge_cc_status{[[ $matchers ]]} == 0",
"group": "Integration",
"attributes": []
},
...
]
Get Trigger Variable Description
GET {{LEM_adminURL}}/admin/v1/instance-alert/trigger/variables/{{LEM_INSTANCE_ALERT_SOURCE_TYPE}}
Get Trigger Variable Description
Returns the list of variables available in trigger subject / message templates for a given source type. Use to build a variable-picker dropdown.
Endpoint
GET {{LEM_adminURL}}/admin/v1/instance-alert/trigger/variables/{{LEM_INSTANCE_ALERT_SOURCE_TYPE}}
Authentication
HTTP Basic Auth. Username is your API token, password is empty. Tokens are managed under System > Access Control > Tokens.
Errors
| HTTP status | When it happens |
|---|---|
400 Bad Request |
Missing or malformed query/body parameter. |
401 Unauthorized |
Missing or invalid credentials. |
403 Forbidden |
Token lacks permission for this operation. |
404 Not Found |
Target entity does not exist. |
5xx |
Service is unreachable, restarting, or internally errored. Inspect device logs under System > Support. |
TLS note: edge devices use a self-signed certificate by default. Either install the device CA in your client trust store or disable certificate verification when calling this endpoint directly.
Response
Status: 0
Delete Trigger
DELETE {{LEM_adminURL}}/admin/v1/instance-alert/trigger/definition/{{trigger_id}}
Delete Trigger
Removes an instance-alert trigger by ID.
Endpoint
DELETE {{LEM_adminURL}}/admin/v1/instance-alert/trigger/definition/{{trigger_id}}
Authentication
HTTP Basic Auth. Username is your API token, password is empty. Tokens are managed under System > Access Control > Tokens.
Errors
| HTTP status | When it happens |
|---|---|
400 Bad Request |
Missing or malformed query/body parameter. |
401 Unauthorized |
Missing or invalid credentials. |
403 Forbidden |
Token lacks permission for this operation. |
404 Not Found |
Target entity does not exist. |
5xx |
Service is unreachable, restarting, or internally errored. Inspect device logs under System > Support. |
TLS note: edge devices use a self-signed certificate by default. Either install the device CA in your client trust store or disable certificate verification when calling this endpoint directly.
Response
Status: 200 OK
{
"code": "S",
"message": null,
"messageDetails": null
}
Send Test Webhook
POST {{LEM_adminURL}}/admin/v1/instance-alert/action/test/webhook
Send Test Webhook
Sends a test message to a webhook action template, returning the response. Use to validate webhook URL + headers before saving.
Endpoint
POST {{LEM_adminURL}}/admin/v1/instance-alert/action/test/webhook
Authentication
HTTP Basic Auth. Username is your API token, password is empty. Tokens are managed under System > Access Control > Tokens.
Request body
{
"id": "string",
"name": "string",
"type": "WEBHOOK",
"webhook": "string",
"verifySsl": true,
"headers": [{ "key": "string", "value": "string" }]
}
Errors
| HTTP status | When it happens |
|---|---|
400 Bad Request |
Missing or malformed query/body parameter. |
401 Unauthorized |
Missing or invalid credentials. |
403 Forbidden |
Token lacks permission for this operation. |
404 Not Found |
Target entity does not exist. |
5xx |
Service is unreachable, restarting, or internally errored. Inspect device logs under System > Support. |
TLS note: edge devices use a self-signed certificate by default. Either install the device CA in your client trust store or disable certificate verification when calling this endpoint directly.
Request Body
{
"id": "string",
"name": "string",
"type": "EMAIL, SLACK, WEBHOOK, PAGERDUTY",
"limit": {
"maxActionsPerInterval": 1073741824,
"updateIntervalSeconds": 1073741824
},
"webhook": "string",
"verifySsl": true,
"method": {},
"headers": [
{
"key": "string",
"value": "string"
}
]
}
Response
Status: 200 OK
{
"code": "S",
"messageDetails": null,
"request": {
"incident_id": "incidentId",
"subject": "Event subject",
"timestamp": "2026-01-09T17:11:34.488Z[UTC]",
"event_action": "resolve",
"source": "EVENTS",
"severity": "0",
"sent_by": "example.domain.name",
"trigger_url": "https://example.domain.name/#/Company name/projectId/alerts/triggers",
"trigger_name": "Trigger name",
"summary": "Event summary",
"project_id": "projectId",
"company": "Company name",
"device_id": "deviceId",
"device_hostname": null,
"device_friendly_name": null,
"alert_source": "EVENTS",
"payload": {
"component_id": null,
"event_id": null,
"event_severity": null,
"event_info": {}
}
},
"response": "\n\n"
}
Delete Action Template
DELETE {{LEM_adminURL}}/admin/v1/instance-alert/action/templates/{{lem_alert_template_id}}
Delete Action Template
Removes an instance-alert action template by ID.
Endpoint
DELETE {{LEM_adminURL}}/admin/v1/instance-alert/action/templates/{{lem_alert_template_id}}
Authentication
HTTP Basic Auth. Username is your API token, password is empty. Tokens are managed under System > Access Control > Tokens.
Errors
| HTTP status | When it happens |
|---|---|
400 Bad Request |
Missing or malformed query/body parameter. |
401 Unauthorized |
Missing or invalid credentials. |
403 Forbidden |
Token lacks permission for this operation. |
404 Not Found |
Target entity does not exist. |
5xx |
Service is unreachable, restarting, or internally errored. Inspect device logs under System > Support. |
TLS note: edge devices use a self-signed certificate by default. Either install the device CA in your client trust store or disable certificate verification when calling this endpoint directly.
Response
Status: 200 OK
{
"code": "S",
"message": null,
"messageDetails": null
}
Create Instance Action Template
POST {{LEM_adminURL}}/admin/v1/instance-alert/action/templates
Create Instance Action Template
Creates a new instance-alert action template (EMAIL / SLACK / WEBHOOK / PAGERDUTY). The body shape varies by type.
Endpoint
POST {{LEM_adminURL}}/admin/v1/instance-alert/action/templates
Authentication
HTTP Basic Auth. Username is your API token, password is empty. Tokens are managed under System > Access Control > Tokens.
Request body
{
"name": "string",
"type": "EMAIL",
"limit": { "maxActionsPerInterval": 10, "updateIntervalSeconds": 3600 },
"recipients": ["string"],
"subject": "string",
"message": "string"
}
Errors
| HTTP status | When it happens |
|---|---|
400 Bad Request |
Missing or malformed query/body parameter. |
401 Unauthorized |
Missing or invalid credentials. |
403 Forbidden |
Token lacks permission for this operation. |
404 Not Found |
Target entity does not exist. |
5xx |
Service is unreachable, restarting, or internally errored. Inspect device logs under System > Support. |
TLS note: edge devices use a self-signed certificate by default. Either install the device CA in your client trust store or disable certificate verification when calling this endpoint directly.
Request Body
{
"id": "string",
"name": "string",
"type": "EMAIL, SLACK, WEBHOOK, PAGERDUTY",
"limit": {
"maxActionsPerInterval": 1073741824,
"updateIntervalSeconds": 1073741824
},
"recipients": [
"string"
],
"subject": "string",
"message": "string"
}
Response
Status: 200 OK
{
"code": "S",
"message": null,
"messageDetails": null
}
Get Instance Action Templates
GET {{LEM_adminURL}}/admin/v1/instance-alert/action/templates
Get Instance Action Templates
Returns the configured instance-alert action templates.
Endpoint
GET {{LEM_adminURL}}/admin/v1/instance-alert/action/templates
Authentication
HTTP Basic Auth. Username is your API token, password is empty. Tokens are managed under System > Access Control > Tokens.
Errors
| HTTP status | When it happens |
|---|---|
400 Bad Request |
Missing or malformed query/body parameter. |
401 Unauthorized |
Missing or invalid credentials. |
403 Forbidden |
Token lacks permission for this operation. |
404 Not Found |
Target entity does not exist. |
5xx |
Service is unreachable, restarting, or internally errored. Inspect device logs under System > Support. |
TLS note: edge devices use a self-signed certificate by default. Either install the device CA in your client trust store or disable certificate verification when calling this endpoint directly.
Response
Status: 200 OK
[
{
"id": "3wjuopprf7a4x5kdlg1o0ga9y",
"name": "Email Alert",
"type": "EMAIL",
"limit": {
"maxActionsPerInterval": 10,
"updateIntervalSeconds": 3600
},
"recipients": [
"user@litmus.io"
],
"subject": null,
"message": null
}
]
Get Edge Events Registry Components
GET {{LEM_adminURL}}/admin/v1/instance-alert/events-registry
Get Edge Events Registry Components
Returns the instance-alert event registry: the components and event IDs that LEM-instance-scoped triggers can match on. Distinct from the per-device event registry under ELM > Edge Devices > Device Details > Events.
Endpoint
GET {{LEM_adminURL}}/admin/v1/instance-alert/events-registry
Authentication
HTTP Basic Auth. Username is your API token, password is empty. Tokens are managed under System > Access Control > Tokens.
Errors
| HTTP status | When it happens |
|---|---|
400 Bad Request |
Missing or malformed query/body parameter. |
401 Unauthorized |
Missing or invalid credentials. |
403 Forbidden |
Token lacks permission for this operation. |
404 Not Found |
Target entity does not exist. |
5xx |
Service is unreachable, restarting, or internally errored. Inspect device logs under System > Support. |
TLS note: edge devices use a self-signed certificate by default. Either install the device CA in your client trust store or disable certificate verification when calling this endpoint directly.
Response
Status: 200 OK
{
"project": {
"id": "project",
"name": "Project",
"config": null,
"events": {
"project.deleted": {
"id": "project.deleted",
"msg": "Project deleted",
"attrs": {
"projectId": {
"name": "projectId",
"type": "string",
"required": false
},
"projectName": {
"name": "projectName",
"type": "string",
"required": false
},
"companyName": {
"name": "companyName",
"type": "string",
"required": false
}
}
},
"project.updated": {
"id": "project.updated",
"msg": "Project updated",
"attrs": {
"projectId": {
"name": "projectId",
"type": "string",
"required": false
},
"projectName": {
"name": "projectName",
"type": "string",
"required": false
},
"companyName": {
"name": "companyName",
"type": "string",
"required": false
}
}
},
"project.created": {
"id": "project.created",
"msg": "Project created",
"attrs": {
"projectId": {
"name": "projectId",
"type": "string",
"required": false
},
"projectName": {
"name": "projectName",
"type": "string",
"required": false
},
"companyName": {
"name": "companyName",
"type": "string",
"required": false
}
}
}
}
}
}