List action policy executions Experimental

GET /api/alerting/v2/execution_history/action_policies

Spaces method and path for this operation:

get /s/{space_id}/api/alerting/v2/execution_history/action_policies

Refer to Spaces for more information.

Get a paginated list of dispatcher summary events for action policies in the current space.

[Required authorization] Route required privileges: read_alerting-v2-execution-history.

Query parameters

  • page integer Required

    Page number (1-indexed). Defaults to 1.

    Minimum value is 1, maximum value is 10000. Default value is 1.

  • per_page integer Required

    Number of events per page. Defaults to 20.

    Minimum value is 1, maximum value is 100. Default value is 20.

  • from string(date-time)

    Inclusive ISO datetime lower bound on the event timestamp; overrides the default 24-hour window. Independent of alert_ids — e.g. set it to an alert’s start time to scope results to that alert’s lifetime.

    Format should match the following pattern: ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$.

  • to string(date-time)

    Inclusive ISO datetime upper bound on the event timestamp.

    Format should match the following pattern: ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$.

  • alert_ids array[string]

    Alert filter. Narrows events to those referencing at least one of the provided alert IDs.

    At least 1 but not more than 50 elements. Minimum length of each is 1, maximum length of each is 150.

  • sort_field string Required

    Sort field. Defaults to "dispatched_at".

    Value is dispatched_at. Default value is dispatched_at.

  • sort_order string Required

    Sort direction. Defaults to "desc".

    Values are asc or desc. Default value is desc.

  • rule_ids array[string]

    Explicit rule filter. Narrows events to those referencing at least one of the provided rule IDs. Also unions with the search filter if both are provided.

    At least 1 but not more than 50 elements. Minimum length of each is 1, maximum length of each is 150.

  • outcomes array[string]

    Outcome filter. When omitted matches all outcomes. Pass one or more of "success", "throttled", "failure" to narrow.

    At least 1 but not more than 3 elements. Values are success, throttled, or failure.

Responses

  • 200 application/json

    Returns a paginated list of execution history events.

    Hide response attributes Show response attributes object
    • items array[object] Required
      Hide items attributes Show items attributes object
      • action_group_count number Required
      • alert_count number Required
      • alerts array[object] Required

        Alert IDs referenced by this event, bounded to 50. Empty when the event references no alerts. Use alert_count for the true total.

        Not more than 50 elements.

        Hide alerts attribute Show alerts attribute object
        • id string Required
      • dispatched_at string(date-time) Required

        Format should match the following pattern: ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$.

      • error object | null Required

        Additional properties are NOT allowed.

        Hide error attributes Show error attributes object | null
        • message string Required
        • stack_trace string | null Required
      • failure_reason string

        Values are missing_api_key, workflow_not_found, workflow_disabled, schedule_error, or license_not_supported.

      • outcome string Required

        Values are success, throttled, or failure.

      • policy object Required

        Additional properties are NOT allowed.

        Hide policy attributes Show policy attributes object
        • id string Required
        • name string | null
      • rule_count number Required

        Number of rules referenced by this event after search or rule-filter narrowing. Unlike total on a list response, this is an exact count and it can exceed rules.length when the embedded array is truncated to the cap.

      • rules array[object] Required

        Rules referenced by this event, bounded to 20. When a search or rule filter narrows the match, this array is intersected with the matched subset server-side. Use rule_count for the full count.

        Not more than 20 elements.

        Hide rules attributes Show rules attributes object
        • id string Required
        • name string | null
      • workflows array[object] Required

        Not more than 100 elements.

        Hide workflows attributes Show workflows attributes object
        • id string Required
        • name string | null
    • page integer Required

      Minimum value is 1, maximum value is 9007199254740991.

    • per_page integer Required

      Minimum value is 1, maximum value is 9007199254740991.

    • search_matches object | null Required

      Per-type match counts for the active search. Null when no search was provided. When is_truncated is true the server ID filter was capped and the result may be truncated.

      Additional properties are NOT allowed.

      Hide search_matches attributes Show search_matches attributes object | null
      • is_truncated boolean Required

        True when the server filter cap was reached and results may be truncated.

      • policies number Required

        Policies matching the search. This count is an estimate: results above 10,000 may be reported as 10,000.

      • rules number Required

        Rules matching the search. This count is an estimate: results above 10,000 may be reported as 10,000.

    • total integer Required

      The number of action policy events matching the query. This count is an estimate: results above 10,000 may be reported as 10,000.

      Minimum value is 0, maximum value is 9007199254740991.

  • 400 application/json

    Indicates an invalid schema or parameters.

    Hide response attributes Show response attributes object
    • code string Required

      Stable error code you can branch on, for example INVALID_SCHEDULE or RULE_ALREADY_EXISTS.

    • details object

      Optional extra information about the error, for example field validation issues or the rule_id when that ID already exists.

      Additional properties are allowed.

    • error string Required

      A short human-readable summary of the error category (e.g., "Not Found", "Bad Request"). Subject to change without notice. Do not parse or rely on its content.

    • message string Required

      A readable explanation of the error. The wording can change without notice. Do not parse this field.

  • 401 application/json

    Indicates the request was not authenticated.

    Hide response attributes Show response attributes object
    • code string Required

      Stable error code you can branch on, for example INVALID_SCHEDULE or RULE_ALREADY_EXISTS.

    • details object

      Optional extra information about the error, for example field validation issues or the rule_id when that ID already exists.

      Additional properties are allowed.

    • error string Required

      A short human-readable summary of the error category (e.g., "Not Found", "Bad Request"). Subject to change without notice. Do not parse or rely on its content.

    • message string Required

      A readable explanation of the error. The wording can change without notice. Do not parse this field.

  • 403 application/json

    Indicates the user does not have the required privileges to perform the request.

    Hide response attributes Show response attributes object
    • code string Required

      Stable error code you can branch on, for example INVALID_SCHEDULE or RULE_ALREADY_EXISTS.

    • details object

      Optional extra information about the error, for example field validation issues or the rule_id when that ID already exists.

      Additional properties are allowed.

    • error string Required

      A short human-readable summary of the error category (e.g., "Not Found", "Bad Request"). Subject to change without notice. Do not parse or rely on its content.

    • message string Required

      A readable explanation of the error. The wording can change without notice. Do not parse this field.

  • 500 application/json

    Indicates an unexpected server-side error.

    Hide response attributes Show response attributes object
    • code string Required

      Stable error code you can branch on, for example INVALID_SCHEDULE or RULE_ALREADY_EXISTS.

    • details object

      Optional extra information about the error, for example field validation issues or the rule_id when that ID already exists.

      Additional properties are allowed.

    • error string Required

      A short human-readable summary of the error category (e.g., "Not Found", "Bad Request"). Subject to change without notice. Do not parse or rely on its content.

    • message string Required

      A readable explanation of the error. The wording can change without notice. Do not parse this field.

  • 503 application/json

    Indicates the alerting engine is disabled by the alerting:v2:enabled advanced setting.

    Hide response attributes Show response attributes object
    • code string Required

      Stable error code you can branch on, for example INVALID_SCHEDULE or RULE_ALREADY_EXISTS.

    • details object

      Optional extra information about the error, for example field validation issues or the rule_id when that ID already exists.

      Additional properties are allowed.

    • error string Required

      A short human-readable summary of the error category (e.g., "Not Found", "Bad Request"). Subject to change without notice. Do not parse or rely on its content.

    • message string Required

      A readable explanation of the error. The wording can change without notice. Do not parse this field.

GET /api/alerting/v2/execution_history/action_policies
curl \
 --request GET 'https://<KIBANA_URL>/api/alerting/v2/execution_history/action_policies?page=1&per_page=20&sort_field=dispatched_at&sort_order=desc' \
 --header "Authorization: $API_KEY"
Response examples (200)
{
  "items": [
    {
      "action_group_count": 1,
      "alert_count": 1,
      "alerts": [
        {
          "id": "episode-1"
        }
      ],
      "dispatched_at": "2026-01-15T12:05:00.000Z",
      "error": null,
      "outcome": "success",
      "policy": {
        "id": "action-policy-1",
        "name": "Notify on production alerts"
      },
      "rule_count": 1,
      "rules": [
        {
          "id": "rule-1",
          "name": "Host CPU high"
        }
      ],
      "workflows": [
        {
          "id": "workflow-1",
          "name": "Notify oncall"
        }
      ]
    }
  ],
  "page": 1,
  "per_page": 20,
  "search_matches": null,
  "total": 1
}
Response examples (400)
{
  "code": "BAD_REQUEST",
  "details": {
    "errors": {
      "page": [
        "page * per_page cannot exceed 10000."
      ]
    }
  },
  "error": "Bad Request",
  "message": "page * per_page cannot exceed 10000."
}
Response examples (401)
{
  "code": "UNAUTHORIZED",
  "error": "Unauthorized",
  "message": "Authentication required to access this API."
}
Response examples (403)
{
  "code": "FORBIDDEN",
  "error": "Forbidden",
  "message": "The current user does not have the required privileges for this request."
}
Response examples (500)
{
  "code": "INTERNAL_SERVER_ERROR",
  "error": "Internal Server Error",
  "message": "An unexpected error occurred."
}
Response examples (503)
{
  "code": "ALERTING_DISABLED",
  "error": "Service Unavailable",
  "message": "Alerting is disabled."
}