Spaces method and path for this operation:
Refer to Spaces for more information.
Apply a partial update to an existing action policy. Fields not present in the body are left unchanged.
[Required authorization] Route required privileges: manage_alerting-v2-action-policies AND read_alerting-v2-rules.
Path parameters
-
The ID of the action policy. Copy it from the response when you create a policy, fetch one policy, or fetch the policy list.
Minimum length is
1, maximum length is150.
Body
-
A description of the action policy.
Maximum length is
1024. -
The list of destinations. At least one is required.
At least
1but not more than10elements. -
The fields used to group alerts.
Not more than
16elements. Minimum length of each is1, maximum length of each is256. -
Selects the alerts this policy applies to. Set
tagsto match alerts from rules with those tags. Setexpressionto a KQL query, which will be evaluated against each alert.
If you set bothtagsandexpression, an alert must match the tags and the expression for the policy to apply. Whenmatcherisnull, or when bothtagsandexpressionare empty, the policy applies to all alerts.
Updatingmatcherreplaces it entirely: to changetagswithout droppingexpression, resend the currentexpressionvalue.Additional properties are NOT allowed.
-
The name of the action policy.
Minimum length is
1, maximum length is256. -
The throttle configuration for notifications.
Additional properties are NOT allowed.
-
The current version of the action policy, used for optimistic concurrency control.
Minimum length is
1, maximum length is256.
Responses
-
Returns the updated action policy.
-
Indicates an invalid schema or parameters.
-
Indicates the request was not authenticated.
-
Indicates the user does not have the required privileges to perform the request.
-
Indicates an action policy with the given ID does not exist.
-
Indicates the action policy was concurrently updated by another caller.
-
Indicates an unexpected server-side error.
-
Indicates the alerting engine is disabled by the
alerting:v2:enabledadvanced setting.
curl \
--request PATCH 'https://localhost:5601/api/alerting/v2/action_policies/{id}' \
--header "Authorization: $API_KEY" \
--header "Content-Type: application/json" \
--header "kbn-xsrf: true" \
--data '{
"description": "Updated description.",
"name": "Notify on production alerts (updated)",
"version": "WzAsMV0="
}'
{
"description": "Updated description.",
"name": "Notify on production alerts (updated)",
"version": "WzAsMV0="
}
{
"auth": {
"created_by_user": true,
"owner": "elastic"
},
"created_at": "2026-01-15T12:00:00.000Z",
"created_by": "elastic",
"description": "Updated description.",
"destinations": [
{
"id": "workflow-1",
"type": "workflow"
}
],
"enabled": true,
"group_by": null,
"grouping_mode": "per_episode",
"id": "action-policy-1",
"matcher": {
"tags": [
"production"
]
},
"name": "Notify on production alerts (updated)",
"snoozed_until": null,
"throttle": {
"interval": null,
"strategy": "on_status_change"
},
"updated_at": "2026-01-15T12:00:00.000Z",
"updated_by": "elastic",
"version": "WzAsMV0="
}
{
"code": "INVALID_ACTION_POLICY_DATA",
"details": {
"context": "update",
"errors": {
"errors": [],
"properties": {
"name": {
"errors": [
"Invalid input: expected string, received undefined"
]
}
}
}
},
"error": "Bad Request",
"message": "Error validating update action policy data - name: Invalid input: expected string, received undefined"
}
{
"code": "UNAUTHORIZED",
"error": "Unauthorized",
"message": "Authentication required to access this API."
}
{
"code": "FORBIDDEN",
"error": "Forbidden",
"message": "The current user does not have the required privileges for this request."
}
{
"code": "ACTION_POLICY_NOT_FOUND",
"details": {
"action_policy_id": "action-policy-1"
},
"error": "Not Found",
"message": "Action policy with ID \"action-policy-1\" not found"
}
{
"code": "ACTION_POLICY_VERSION_CONFLICT",
"details": {
"action_policy_id": "action-policy-1"
},
"error": "Conflict",
"message": "Action policy with ID \"action-policy-1\" has already been updated by another user"
}
{
"code": "INTERNAL_SERVER_ERROR",
"error": "Internal Server Error",
"message": "An unexpected error occurred."
}
{
"code": "ALERTING_DISABLED",
"error": "Service Unavailable",
"message": "Alerting is disabled."
}