The ID of the action policy. Copy it from the response when you create a policy, fetch one policy, or fetch the policy list.
Minimum length is 1, maximum length is 150.
application/json
Body
snoozed_until
string(date-time)Required
The ISO datetime until which the action policy should be snoozed.
Format should match the following pattern: ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$.
one notification per alert episode lifecycle (default).
Value is per_episode.
a single notification for all matching episodes.
Value is all.
group by specified groupBy fields.
Value is per_field.
id
stringRequired
The unique identifier for the action policy.
matcher
object | nullRequired
Selects the alerts this policy applies to. Set tags to match alerts from rules with those tags. Set expression to a KQL query, which will be evaluated against each alert.
If you set both tags and expression, an alert must match the tags and the expression for the policy to apply. When matcher is null, or when both tags and expression are empty, the policy applies to all alerts.
A KQL query that's evaluated against each alert. Supported fields are: episode_id, episode_status, group_hash, last_event_timestamp, severity, and your rule's query output columns under data.* (for example, data.host.name). Referencing other fields won't work. Omit matcher.expression or set it to null to match on tags alone.
Maximum length is 4096.
tags
array[string] | null
Rule tags this policy should match. The policy applies to alerts from any rule that has at least one of these tags. Omit matcher.tags or set it to null to match on matcher.expression alone.
Not more than 50 elements. Minimum length of each is 1, maximum length of each is 256.
name
stringRequired
The name of the action policy.
snoozed_until
string | nullRequired
The ISO datetime until which the policy is snoozed, or null if not snoozed.
Stable error code you can branch on, for example INVALID_SCHEDULE or RULE_ALREADY_EXISTS.
details
object
Optional extra information about the error, for example field validation issues or the rule_id when that ID already exists.
Additional properties are allowed.
error
stringRequired
A short human-readable summary of the error category (e.g., "Not Found", "Bad Request"). Subject to change without notice. Do not parse or rely on its content.
message
stringRequired
A readable explanation of the error. The wording can change without notice. Do not parse this field.
Stable error code you can branch on, for example INVALID_SCHEDULE or RULE_ALREADY_EXISTS.
details
object
Optional extra information about the error, for example field validation issues or the rule_id when that ID already exists.
Additional properties are allowed.
error
stringRequired
A short human-readable summary of the error category (e.g., "Not Found", "Bad Request"). Subject to change without notice. Do not parse or rely on its content.
message
stringRequired
A readable explanation of the error. The wording can change without notice. Do not parse this field.
403
application/json
Indicates the user does not have the required privileges to perform the request.
Stable error code you can branch on, for example INVALID_SCHEDULE or RULE_ALREADY_EXISTS.
details
object
Optional extra information about the error, for example field validation issues or the rule_id when that ID already exists.
Additional properties are allowed.
error
stringRequired
A short human-readable summary of the error category (e.g., "Not Found", "Bad Request"). Subject to change without notice. Do not parse or rely on its content.
message
stringRequired
A readable explanation of the error. The wording can change without notice. Do not parse this field.
404
application/json
Indicates an action policy with the given ID does not exist.
Stable error code you can branch on, for example INVALID_SCHEDULE or RULE_ALREADY_EXISTS.
details
object
Optional extra information about the error, for example field validation issues or the rule_id when that ID already exists.
Additional properties are allowed.
error
stringRequired
A short human-readable summary of the error category (e.g., "Not Found", "Bad Request"). Subject to change without notice. Do not parse or rely on its content.
message
stringRequired
A readable explanation of the error. The wording can change without notice. Do not parse this field.
409
application/json
Indicates the action policy was concurrently updated by another caller.
Stable error code you can branch on, for example INVALID_SCHEDULE or RULE_ALREADY_EXISTS.
details
object
Optional extra information about the error, for example field validation issues or the rule_id when that ID already exists.
Additional properties are allowed.
error
stringRequired
A short human-readable summary of the error category (e.g., "Not Found", "Bad Request"). Subject to change without notice. Do not parse or rely on its content.
message
stringRequired
A readable explanation of the error. The wording can change without notice. Do not parse this field.
Stable error code you can branch on, for example INVALID_SCHEDULE or RULE_ALREADY_EXISTS.
details
object
Optional extra information about the error, for example field validation issues or the rule_id when that ID already exists.
Additional properties are allowed.
error
stringRequired
A short human-readable summary of the error category (e.g., "Not Found", "Bad Request"). Subject to change without notice. Do not parse or rely on its content.
message
stringRequired
A readable explanation of the error. The wording can change without notice. Do not parse this field.
503
application/json
Indicates the alerting engine is disabled by the alerting:v2:enabled advanced setting.
Stable error code you can branch on, for example INVALID_SCHEDULE or RULE_ALREADY_EXISTS.
details
object
Optional extra information about the error, for example field validation issues or the rule_id when that ID already exists.
Additional properties are allowed.
error
stringRequired
A short human-readable summary of the error category (e.g., "Not Found", "Bad Request"). Subject to change without notice. Do not parse or rely on its content.
message
stringRequired
A readable explanation of the error. The wording can change without notice. Do not parse this field.
POST
/api/alerting/v2/action_policies/{id}/_snooze
{
"code": "UNAUTHORIZED",
"error": "Unauthorized",
"message": "Authentication required to access this API."
}
Response examples (403)
{
"code": "FORBIDDEN",
"error": "Forbidden",
"message": "The current user does not have the required privileges for this request."
}
Response examples (404)
{
"code": "ACTION_POLICY_NOT_FOUND",
"details": {
"action_policy_id": "action-policy-1"
},
"error": "Not Found",
"message": "Action policy with ID \"action-policy-1\" not found"
}
Response examples (409)
{
"code": "ACTION_POLICY_VERSION_CONFLICT",
"details": {
"action_policy_id": "action-policy-1"
},
"error": "Conflict",
"message": "Action policy with ID \"action-policy-1\" has already been updated by another user"
}