---
title: Create rules
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/python)

[Magic Network Monitoring](https://developers.cloudflare.com/api/python/resources/magic_network_monitoring)

[Rules](https://developers.cloudflare.com/api/python/resources/magic_network_monitoring/subresources/rules)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Create rules

magic\_network\_monitoring.rules.create(RuleCreateParams\*\*kwargs) -> [MagicNetworkMonitoringRule](<https://developers.cloudflare.com/api/python/resources/magic_network_monitoring#(resource)%20magic_network_monitoring.rules%20%3E%20(model)%20magic_network_monitoring_rule%20%3E%20(schema)>)

POST/accounts/{account\_id}/mnm/rules

Create network monitoring rules for account. Currently only supports creating a single rule per API request.

##### Security

API Email + API Key

The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

**Example:**`X-Auth-Email: user@example.com`

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

**Example:**`X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194`

##### Accepted Permissions (at least one required)

`Magic Network Monitoring Admin`

##### ParametersExpand Collapse

account\_id: str

[Link to this property](<#(resource)%20magic_network_monitoring.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20account_id%20%3E%20(schema)>)

automatic\_advertisement: Optional\[bool]

Toggle on if you would like Cloudflare to automatically advertise the IP Prefixes within the rule via Magic Transit when the rule is triggered. Only available for users of Magic Transit.

[Link to this property](<#(resource)%20magic_network_monitoring.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20automatic_advertisement%20%3E%20(schema)>)

name: str

The name of the rule. Must be unique. Supports characters A-Z, a-z, 0-9, underscore (\_), dash (-), period (.), and tilde (\~). You can’t have a space in the rule name. Max 256 characters.

[Link to this property](<#(resource)%20magic_network_monitoring.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20name%20%3E%20(schema)>)

prefixes: Sequence\[str]

[Link to this property](<#(resource)%20magic_network_monitoring.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20prefixes%20%3E%20(schema)>)

<details>

<summary>

type: Literal\["threshold", "zscore", "advanced\_ddos"]

MNM rule type.

</summary>

One of the following:

"threshold"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"zscore"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"advanced\_ddos"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

</details>

[Link to this property](<#(resource)%20magic_network_monitoring.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20type%20%3E%20(schema)>)

bandwidth\_threshold: Optional\[float]

The number of bits per second for the rule. When this value is exceeded for the set duration, an alert notification is sent. Minimum of 1 and no maximum.

minimum1

[Link to this property](<#(resource)%20magic_network_monitoring.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20bandwidth_threshold%20%3E%20(schema)>)

<details>

<summary>

duration: Optional\[Literal\["1m", "5m", "10m", 5 more]]

The amount of time that the rule threshold must be exceeded to send an alert notification. The final value must be equivalent to one of the following 8 values \[“1m”,“5m”,“10m”,“15m”,“20m”,“30m”,“45m”,“60m”].

</summary>

One of the following:

"1m"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20duration%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"5m"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20duration%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"10m"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20duration%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

"15m"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20duration%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

"20m"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20duration%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

"30m"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20duration%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

"45m"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20duration%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

"60m"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20duration%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

</details>

[Link to this property](<#(resource)%20magic_network_monitoring.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20duration%20%3E%20(schema)>)

packet\_threshold: Optional\[float]

The number of packets per second for the rule. When this value is exceeded for the set duration, an alert notification is sent. Minimum of 1 and no maximum.

minimum1

[Link to this property](<#(resource)%20magic_network_monitoring.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20packet_threshold%20%3E%20(schema)>)

<details>

<summary>

prefix\_match: Optional\[Literal\["exact", "subnet", "supernet"]]

Prefix match type to be applied for a prefix auto advertisement when using an advanced\_ddos rule.

</summary>

One of the following:

"exact"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20prefix_match%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"subnet"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20prefix_match%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"supernet"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20prefix_match%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

</details>

[Link to this property](<#(resource)%20magic_network_monitoring.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20prefix_match%20%3E%20(schema)>)

<details>

<summary>

zscore\_sensitivity: Optional\[Literal\["low", "medium", "high"]]

Level of sensitivity set for zscore rules.

</summary>

One of the following:

"low"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20zscore_sensitivity%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"medium"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20zscore_sensitivity%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"high"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20zscore_sensitivity%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

</details>

[Link to this property](<#(resource)%20magic_network_monitoring.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20zscore_sensitivity%20%3E%20(schema)>)

<details>

<summary>

zscore\_target: Optional\[Literal\["bits", "packets"]]

Target of the zscore rule analysis.

</summary>

One of the following:

"bits"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20zscore_target%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"packets"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20zscore_target%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

</details>

[Link to this property](<#(resource)%20magic_network_monitoring.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20zscore_target%20%3E%20(schema)>)

##### ReturnsExpand Collapse

<details>

<summary>

class MagicNetworkMonitoringRule: …

</summary>

id: str

The id of the rule. Must be unique.

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(model)%20magic_network_monitoring_rule%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

automatic\_advertisement: Optional\[bool]

Toggle on if you would like Cloudflare to automatically advertise the IP Prefixes within the rule via Magic Transit when the rule is triggered. Only available for users of Magic Transit.

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(model)%20magic_network_monitoring_rule%20%3E%20(schema)%20%3E%20(property)%20automatic_advertisement">Link to this property</a>

name: str

The name of the rule. Must be unique. Supports characters A-Z, a-z, 0-9, underscore (\_), dash (-), period (.), and tilde (\~). You can’t have a space in the rule name. Max 256 characters.

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(model)%20magic_network_monitoring_rule%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

prefixes: List\[str]

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(model)%20magic_network_monitoring_rule%20%3E%20(schema)%20%3E%20(property)%20prefixes">Link to this property</a>

<details>

<summary>

type: Literal\["threshold", "zscore", "advanced\_ddos"]

MNM rule type.

</summary>

One of the following:

"threshold"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(model)%20magic_network_monitoring_rule%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

"zscore"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(model)%20magic_network_monitoring_rule%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

"advanced\_ddos"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(model)%20magic_network_monitoring_rule%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(model)%20magic_network_monitoring_rule%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

bandwidth\_threshold: Optional\[float]

The number of bits per second for the rule. When this value is exceeded for the set duration, an alert notification is sent. Minimum of 1 and no maximum.

minimum1

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(model)%20magic_network_monitoring_rule%20%3E%20(schema)%20%3E%20(property)%20bandwidth_threshold">Link to this property</a>

<details>

<summary>

duration: Optional\[Literal\["1m", "5m", "10m", 5 more]]

The amount of time that the rule threshold must be exceeded to send an alert notification. The final value must be equivalent to one of the following 8 values \[“1m”,“5m”,“10m”,“15m”,“20m”,“30m”,“45m”,“60m”].

</summary>

One of the following:

"1m"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(model)%20magic_network_monitoring_rule%20%3E%20(schema)%20%3E%20(property)%20duration%20%3E%20(member)%200">Link to this property</a>

"5m"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(model)%20magic_network_monitoring_rule%20%3E%20(schema)%20%3E%20(property)%20duration%20%3E%20(member)%201">Link to this property</a>

"10m"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(model)%20magic_network_monitoring_rule%20%3E%20(schema)%20%3E%20(property)%20duration%20%3E%20(member)%202">Link to this property</a>

"15m"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(model)%20magic_network_monitoring_rule%20%3E%20(schema)%20%3E%20(property)%20duration%20%3E%20(member)%203">Link to this property</a>

"20m"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(model)%20magic_network_monitoring_rule%20%3E%20(schema)%20%3E%20(property)%20duration%20%3E%20(member)%204">Link to this property</a>

"30m"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(model)%20magic_network_monitoring_rule%20%3E%20(schema)%20%3E%20(property)%20duration%20%3E%20(member)%205">Link to this property</a>

"45m"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(model)%20magic_network_monitoring_rule%20%3E%20(schema)%20%3E%20(property)%20duration%20%3E%20(member)%206">Link to this property</a>

"60m"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(model)%20magic_network_monitoring_rule%20%3E%20(schema)%20%3E%20(property)%20duration%20%3E%20(member)%207">Link to this property</a>

</details>

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(model)%20magic_network_monitoring_rule%20%3E%20(schema)%20%3E%20(property)%20duration">Link to this property</a>

packet\_threshold: Optional\[float]

The number of packets per second for the rule. When this value is exceeded for the set duration, an alert notification is sent. Minimum of 1 and no maximum.

minimum1

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(model)%20magic_network_monitoring_rule%20%3E%20(schema)%20%3E%20(property)%20packet_threshold">Link to this property</a>

<details>

<summary>

prefix\_match: Optional\[Literal\["exact", "subnet", "supernet"]]

Prefix match type to be applied for a prefix auto advertisement when using an advanced\_ddos rule.

</summary>

One of the following:

"exact"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(model)%20magic_network_monitoring_rule%20%3E%20(schema)%20%3E%20(property)%20prefix_match%20%3E%20(member)%200">Link to this property</a>

"subnet"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(model)%20magic_network_monitoring_rule%20%3E%20(schema)%20%3E%20(property)%20prefix_match%20%3E%20(member)%201">Link to this property</a>

"supernet"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(model)%20magic_network_monitoring_rule%20%3E%20(schema)%20%3E%20(property)%20prefix_match%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(model)%20magic_network_monitoring_rule%20%3E%20(schema)%20%3E%20(property)%20prefix_match">Link to this property</a>

<details>

<summary>

zscore\_sensitivity: Optional\[Literal\["low", "medium", "high"]]

Level of sensitivity set for zscore rules.

</summary>

One of the following:

"low"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(model)%20magic_network_monitoring_rule%20%3E%20(schema)%20%3E%20(property)%20zscore_sensitivity%20%3E%20(member)%200">Link to this property</a>

"medium"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(model)%20magic_network_monitoring_rule%20%3E%20(schema)%20%3E%20(property)%20zscore_sensitivity%20%3E%20(member)%201">Link to this property</a>

"high"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(model)%20magic_network_monitoring_rule%20%3E%20(schema)%20%3E%20(property)%20zscore_sensitivity%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(model)%20magic_network_monitoring_rule%20%3E%20(schema)%20%3E%20(property)%20zscore_sensitivity">Link to this property</a>

<details>

<summary>

zscore\_target: Optional\[Literal\["bits", "packets"]]

Target of the zscore rule analysis.

</summary>

One of the following:

"bits"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(model)%20magic_network_monitoring_rule%20%3E%20(schema)%20%3E%20(property)%20zscore_target%20%3E%20(member)%200">Link to this property</a>

"packets"

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(model)%20magic_network_monitoring_rule%20%3E%20(schema)%20%3E%20(property)%20zscore_target%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20magic_network_monitoring.rules%20%3E%20(model)%20magic_network_monitoring_rule%20%3E%20(schema)%20%3E%20(property)%20zscore_target">Link to this property</a>

</details>

[Link to this property](<#(resource)%20magic_network_monitoring.rules%20%3E%20(model)%20magic_network_monitoring_rule%20%3E%20(schema)>)

### Create rules

Python

HTTPTypeScriptPythonGoTerraform

```
import os
from cloudflare import Cloudflare

client = Cloudflare(
    api_email=os.environ.get("CLOUDFLARE_EMAIL"),  # This is the default and can be omitted
    api_key=os.environ.get("CLOUDFLARE_API_KEY"),  # This is the default and can be omitted
)
magic_network_monitoring_rule = client.magic_network_monitoring.rules.create(
    account_id="6f91088a406011ed95aed352566e8d4c",
    automatic_advertisement=True,
    name="my_rule_1",
    prefixes=["203.0.113.1/32"],
    type="zscore",
)
print(magic_network_monitoring_rule.id)
```

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "result": {
    "id": "2890e6fa406311ed9b5a23f70f6fb8cf",
    "automatic_advertisement": true,
    "name": "my_rule_1",
    "prefixes": [
      "203.0.113.1/32"
    ],
    "type": "zscore",
    "bandwidth_threshold": 1000,
    "duration": "1m",
    "packet_threshold": 10000,
    "prefix_match": "exact",
    "zscore_sensitivity": "high",
    "zscore_target": "bits"
  },
  "success": true
}
```

##### Returns Examples

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "result": {
    "id": "2890e6fa406311ed9b5a23f70f6fb8cf",
    "automatic_advertisement": true,
    "name": "my_rule_1",
    "prefixes": [
      "203.0.113.1/32"
    ],
    "type": "zscore",
    "bandwidth_threshold": 1000,
    "duration": "1m",
    "packet_threshold": 10000,
    "prefix_match": "exact",
    "zscore_sensitivity": "high",
    "zscore_target": "bits"
  },
  "success": true
}
```