Spaces method and path for this operation:
Refer to Spaces for more information.
Get a paginated list of dispatcher summary events for action policies in the current space.
[Required authorization] Route required privileges: read_alerting-v2-execution-history.
Query parameters
-
Page number (1-indexed). Defaults to 1.
Minimum value is
1, maximum value is10000. Default value is1. -
Number of events per page. Defaults to 20.
Minimum value is
1, maximum value is100. Default value is20. -
Inclusive ISO datetime lower bound on the event timestamp; overrides the default 24-hour window. Independent of alert_ids — e.g. set it to an alert’s start time to scope results to that alert’s lifetime.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
Inclusive ISO datetime upper bound on the event timestamp.
Format should match the following pattern:
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$. -
Alert filter. Narrows events to those referencing at least one of the provided alert IDs.
At least
1but not more than50elements. Minimum length of each is1, maximum length of each is150. -
Sort field. Defaults to "dispatched_at".
Value is
dispatched_at. Default value isdispatched_at. -
Sort direction. Defaults to "desc".
Values are
ascordesc. Default value isdesc. -
Free-text search. Matches policy name, rule name, policy/rule ID (case-insensitive).
Minimum length is
1, maximum length is256. -
Explicit rule filter. Narrows events to those referencing at least one of the provided rule IDs. Also unions with the search filter if both are provided.
At least
1but not more than50elements. Minimum length of each is1, maximum length of each is150. -
Outcome filter. When omitted matches all outcomes. Pass one or more of "success", "throttled", "failure" to narrow.
At least
1but not more than3elements. Values aresuccess,throttled, orfailure.
Responses
-
Returns a paginated list of execution history events.
-
Indicates an invalid schema or parameters.
-
Indicates the request was not authenticated.
-
Indicates the user does not have the required privileges to perform the request.
-
Indicates an unexpected server-side error.
-
Indicates the alerting engine is disabled by the
alerting:v2:enabledadvanced setting.
curl \
--request GET 'https://<KIBANA_URL>/api/alerting/v2/execution_history/action_policies?page=1&per_page=20&sort_field=dispatched_at&sort_order=desc' \
--header "Authorization: $API_KEY"
{
"items": [
{
"action_group_count": 1,
"alert_count": 1,
"alerts": [
{
"id": "episode-1"
}
],
"dispatched_at": "2026-01-15T12:05:00.000Z",
"error": null,
"outcome": "success",
"policy": {
"id": "action-policy-1",
"name": "Notify on production alerts"
},
"rule_count": 1,
"rules": [
{
"id": "rule-1",
"name": "Host CPU high"
}
],
"workflows": [
{
"id": "workflow-1",
"name": "Notify oncall"
}
]
}
],
"page": 1,
"per_page": 20,
"search_matches": null,
"total": 1
}
{
"code": "BAD_REQUEST",
"details": {
"errors": {
"page": [
"page * per_page cannot exceed 10000."
]
}
},
"error": "Bad Request",
"message": "page * per_page cannot exceed 10000."
}
{
"code": "UNAUTHORIZED",
"error": "Unauthorized",
"message": "Authentication required to access this API."
}
{
"code": "FORBIDDEN",
"error": "Forbidden",
"message": "The current user does not have the required privileges for this request."
}
{
"code": "INTERNAL_SERVER_ERROR",
"error": "Internal Server Error",
"message": "An unexpected error occurred."
}
{
"code": "ALERTING_DISABLED",
"error": "Service Unavailable",
"message": "Alerting is disabled."
}