Spaces method and path for this operation:
Refer to Spaces for more information.
Creates an action policy with a server-generated identifier. To create or replace an action policy with a client-supplied identifier, use PUT /api/alerting/v2/action_policies/{id}/.
[Required authorization] Route required privileges: manage_alerting-v2-action-policies AND read_alerting-v2-rules.
Body
-
A description of the action policy.
Maximum length is
1024. -
The list of destinations. At least one is required.
At least
1but not more than10elements. -
The fields used to group alerts.
Not more than
16elements. Minimum length of each is1, maximum length of each is256. -
Selects the alerts this policy applies to. Set
tagsto match alerts from rules with those tags. Setexpressionto a KQL query, which will be evaluated against each alert.
If you set bothtagsandexpression, an alert must match the tags and the expression for the policy to apply. Whenmatcherisnull, or when bothtagsandexpressionare empty, the policy applies to all alerts.Additional properties are NOT allowed.
-
The name of the action policy.
Minimum length is
1, maximum length is256. -
The throttle configuration for notifications.
Additional properties are NOT allowed.
Responses
-
Returns the newly created action policy.
-
Indicates an invalid schema or parameters.
-
Indicates the request was not authenticated.
-
Indicates the user does not have the required privileges to perform the request.
-
Indicates an unexpected server-side error.
-
Indicates the alerting engine is disabled by the
alerting:v2:enabledadvanced setting.
curl \
--request POST 'https://localhost:5601/api/alerting/v2/action_policies' \
--header "Authorization: $API_KEY" \
--header "Content-Type: application/json" \
--header "kbn-xsrf: true" \
--data '{
"description": "Sends notifications for alerts generated by rules with the production tag.",
"destinations": [
{
"id": "workflow-1",
"type": "workflow"
}
],
"grouping_mode": "per_episode",
"matcher": {
"tags": [
"production"
]
},
"name": "Notify on production alerts",
"throttle": {
"strategy": "on_status_change"
}
}'
{
"description": "Sends notifications for alerts generated by rules with the production tag.",
"destinations": [
{
"id": "workflow-1",
"type": "workflow"
}
],
"grouping_mode": "per_episode",
"matcher": {
"tags": [
"production"
]
},
"name": "Notify on production alerts",
"throttle": {
"strategy": "on_status_change"
}
}
{
"auth": {
"created_by_user": true,
"owner": "elastic"
},
"created_at": "2026-01-15T12:00:00.000Z",
"created_by": "elastic",
"description": "Sends notifications for alerts generated by rules with the production tag.",
"destinations": [
{
"id": "workflow-1",
"type": "workflow"
}
],
"enabled": true,
"group_by": null,
"grouping_mode": "per_episode",
"id": "action-policy-1",
"matcher": {
"tags": [
"production"
]
},
"name": "Notify on production alerts",
"snoozed_until": null,
"throttle": {
"interval": null,
"strategy": "on_status_change"
},
"updated_at": "2026-01-15T12:00:00.000Z",
"updated_by": "elastic",
"version": "WzAsMV0="
}
{
"code": "INVALID_ACTION_POLICY_DATA",
"details": {
"context": "create",
"errors": {
"errors": [],
"properties": {
"name": {
"errors": [
"Invalid input: expected string, received undefined"
]
}
}
}
},
"error": "Bad Request",
"message": "Error validating create action policy data - name: Invalid input: expected string, received undefined"
}
{
"code": "UNAUTHORIZED",
"error": "Unauthorized",
"message": "Authentication required to access this API."
}
{
"code": "FORBIDDEN",
"error": "Forbidden",
"message": "The current user does not have the required privileges for this request."
}
{
"code": "INTERNAL_SERVER_ERROR",
"error": "Internal Server Error",
"message": "An unexpected error occurred."
}
{
"code": "ALERTING_DISABLED",
"error": "Service Unavailable",
"message": "Alerting is disabled."
}