Spaces method and path for this operation:
Refer to Spaces for more information.
Creates an action policy with the given identifier, or fully replaces it if one already exists.
[Required authorization] Route required privileges: manage_alerting-v2-action-policies AND read_alerting-v2-rules.
Path parameters
-
The ID of the action policy. Copy it from the response when you create a policy, fetch one policy, or fetch the policy list.
Minimum length is
1, maximum length is150.
Body
-
A description of the action policy.
Maximum length is
1024. -
The list of destinations. At least one is required.
At least
1but not more than10elements. -
The fields used to group alerts.
Not more than
16elements. Minimum length of each is1, maximum length of each is256. -
Selects the alerts this policy applies to. Set
tagsto match alerts from rules with those tags. Setexpressionto a KQL query, which will be evaluated against each alert.
If you set bothtagsandexpression, an alert must match the tags and the expression for the policy to apply. Whenmatcherisnull, or when bothtagsandexpressionare empty, the policy applies to all alerts.Additional properties are NOT allowed.
-
The name of the action policy.
Minimum length is
1, maximum length is256. -
The throttle configuration for notifications.
Additional properties are NOT allowed.
Responses
-
Returns the replaced action policy.
-
Returns the newly created action policy.
-
Indicates an invalid schema or parameters.
-
Indicates the request was not authenticated.
-
Indicates the user does not have the required privileges to perform the request.
-
Indicates the action policy was created or updated concurrently by another caller.
-
Indicates an unexpected server-side error.
-
Indicates the alerting engine is disabled by the
alerting:v2:enabledadvanced setting.
curl \
--request PUT 'https://localhost:5601/api/alerting/v2/action_policies/{id}' \
--header "Authorization: $API_KEY" \
--header "Content-Type: application/json" \
--header "kbn-xsrf: true" \
--data '{
"description": "Sends notifications for alerts generated by rules with the production tag.",
"destinations": [
{
"id": "workflow-1",
"type": "workflow"
}
],
"grouping_mode": "per_episode",
"matcher": {
"tags": [
"production"
]
},
"name": "Notify on production alerts",
"throttle": {
"strategy": "on_status_change"
}
}'
{
"description": "Sends notifications for alerts generated by rules with the production tag.",
"destinations": [
{
"id": "workflow-1",
"type": "workflow"
}
],
"grouping_mode": "per_episode",
"matcher": {
"tags": [
"production"
]
},
"name": "Notify on production alerts",
"throttle": {
"strategy": "on_status_change"
}
}
{
"auth": {
"created_by_user": true,
"owner": "elastic"
},
"created_at": "2026-01-15T12:00:00.000Z",
"created_by": "elastic",
"description": "Sends notifications for alerts generated by rules with the production tag.",
"destinations": [
{
"id": "workflow-1",
"type": "workflow"
}
],
"enabled": true,
"group_by": null,
"grouping_mode": "per_episode",
"id": "action-policy-1",
"matcher": {
"tags": [
"production"
]
},
"name": "Notify on production alerts",
"snoozed_until": null,
"throttle": {
"interval": null,
"strategy": "on_status_change"
},
"updated_at": "2026-01-15T12:00:00.000Z",
"updated_by": "elastic",
"version": "WzAsMV0="
}
{
"auth": {
"created_by_user": true,
"owner": "elastic"
},
"created_at": "2026-01-15T12:00:00.000Z",
"created_by": "elastic",
"description": "Sends notifications for alerts generated by rules with the production tag.",
"destinations": [
{
"id": "workflow-1",
"type": "workflow"
}
],
"enabled": true,
"group_by": null,
"grouping_mode": "per_episode",
"id": "action-policy-1",
"matcher": {
"tags": [
"production"
]
},
"name": "Notify on production alerts",
"snoozed_until": null,
"throttle": {
"interval": null,
"strategy": "on_status_change"
},
"updated_at": "2026-01-15T12:00:00.000Z",
"updated_by": "elastic",
"version": "WzAsMV0="
}
{
"code": "INVALID_ACTION_POLICY_DATA",
"details": {
"context": "upsert",
"errors": {
"errors": [],
"properties": {
"name": {
"errors": [
"Invalid input: expected string, received undefined"
]
}
}
}
},
"error": "Bad Request",
"message": "Error validating upsert action policy data - name: Invalid input: expected string, received undefined"
}
{
"code": "UNAUTHORIZED",
"error": "Unauthorized",
"message": "Authentication required to access this API."
}
{
"code": "FORBIDDEN",
"error": "Forbidden",
"message": "The current user does not have the required privileges for this request."
}
{
"code": "ACTION_POLICY_VERSION_CONFLICT",
"details": {
"action_policy_id": "action-policy-1"
},
"error": "Conflict",
"message": "Action policy with ID \"action-policy-1\" has already been updated by another user"
}
{
"code": "INTERNAL_SERVER_ERROR",
"error": "Internal Server Error",
"message": "An unexpected error occurred."
}
{
"code": "ALERTING_DISABLED",
"error": "Service Unavailable",
"message": "Alerting is disabled."
}