The ID of the action policy. Copy it from the response when you create a policy, fetch one policy, or fetch the policy list. Chosen at creation and permanent — it cannot be changed afterwards. Re-using the id of a deleted resource is allowed but discouraged: execution history, change history, and alert episodes recorded under that id are retained and are attributed to the new resource. Ids appear in URLs and logs, so keep them free of sensitive data.
Minimum length is 1, maximum length is 150. Format should match the following pattern: ^[a-zA-Z0-9_-]+$.
The ISO datetime when the action policy was created.
Format should match the following pattern: ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$.
Selects the alerts this policy applies to. Set tags to match alerts from rules with those routing tags. Set expression to a KQL query, which will be evaluated against each alert.
If you set both tags and expression, an alert must match the tags and the expression for the policy to apply. When matcher is null, or when both tags and expression are empty, the policy applies to all alerts.
A KQL query that's evaluated against each alert. Supported fields are: alert_id, alert_status, group_hash, last_event_timestamp, severity, and your rule's query output columns under data.* (for example, data.host.name). Referencing other fields won't work. Omit matcher.expression or set it to null to match on tags alone.
Maximum length is 4096.
tags
array[string] | null
Routing tags this policy should match. The policy applies to alerts from any rule whose metadata.routing_tags include at least one of these tags. Omit matcher.tags or set it to null to match on matcher.expression alone.
Not more than 50 elements. Minimum length of each is 1, maximum length of each is 128.
name
stringRequired
The name of the action policy.
snoozed_until
string | nullRequired
The ISO datetime until which the policy is snoozed, or null if not snoozed.
notify only on alert status transitions (default for per_alert).
Value is on_status_change.
notify on transitions and at regular intervals.
Value is per_status_interval.
notify at regular intervals regardless of status (default for all/per_field).
Value is time_interval.
notify on every evaluation cycle (high volume).
Value is every_time.
updated_at
string(date-time)Required
The ISO datetime when the action policy was last updated.
Format should match the following pattern: ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$.
Stable error code you can branch on, for example INVALID_SCHEDULE or RULE_ALREADY_EXISTS.
details
object
Optional extra information about the error, for example field validation issues or the rule_id when that ID already exists.
Additional properties are allowed.
error
stringRequired
A short human-readable summary of the error category (e.g., "Not Found", "Bad Request"). Subject to change without notice. Do not parse or rely on its content.
message
stringRequired
A readable explanation of the error. The wording can change without notice. Do not parse this field.
Stable error code you can branch on, for example INVALID_SCHEDULE or RULE_ALREADY_EXISTS.
details
object
Optional extra information about the error, for example field validation issues or the rule_id when that ID already exists.
Additional properties are allowed.
error
stringRequired
A short human-readable summary of the error category (e.g., "Not Found", "Bad Request"). Subject to change without notice. Do not parse or rely on its content.
message
stringRequired
A readable explanation of the error. The wording can change without notice. Do not parse this field.
403
application/json
Indicates the user does not have the required privileges to perform the request.
Stable error code you can branch on, for example INVALID_SCHEDULE or RULE_ALREADY_EXISTS.
details
object
Optional extra information about the error, for example field validation issues or the rule_id when that ID already exists.
Additional properties are allowed.
error
stringRequired
A short human-readable summary of the error category (e.g., "Not Found", "Bad Request"). Subject to change without notice. Do not parse or rely on its content.
message
stringRequired
A readable explanation of the error. The wording can change without notice. Do not parse this field.
404
application/json
Indicates an action policy with the given ID does not exist.
Stable error code you can branch on, for example INVALID_SCHEDULE or RULE_ALREADY_EXISTS.
details
object
Optional extra information about the error, for example field validation issues or the rule_id when that ID already exists.
Additional properties are allowed.
error
stringRequired
A short human-readable summary of the error category (e.g., "Not Found", "Bad Request"). Subject to change without notice. Do not parse or rely on its content.
message
stringRequired
A readable explanation of the error. The wording can change without notice. Do not parse this field.
409
application/json
Indicates the action policy was concurrently updated by another caller.
Stable error code you can branch on, for example INVALID_SCHEDULE or RULE_ALREADY_EXISTS.
details
object
Optional extra information about the error, for example field validation issues or the rule_id when that ID already exists.
Additional properties are allowed.
error
stringRequired
A short human-readable summary of the error category (e.g., "Not Found", "Bad Request"). Subject to change without notice. Do not parse or rely on its content.
message
stringRequired
A readable explanation of the error. The wording can change without notice. Do not parse this field.
Stable error code you can branch on, for example INVALID_SCHEDULE or RULE_ALREADY_EXISTS.
details
object
Optional extra information about the error, for example field validation issues or the rule_id when that ID already exists.
Additional properties are allowed.
error
stringRequired
A short human-readable summary of the error category (e.g., "Not Found", "Bad Request"). Subject to change without notice. Do not parse or rely on its content.
message
stringRequired
A readable explanation of the error. The wording can change without notice. Do not parse this field.
503
application/json
Indicates the alerting engine is disabled by the alerting:v2:enabled advanced setting.
Stable error code you can branch on, for example INVALID_SCHEDULE or RULE_ALREADY_EXISTS.
details
object
Optional extra information about the error, for example field validation issues or the rule_id when that ID already exists.
Additional properties are allowed.
error
stringRequired
A short human-readable summary of the error category (e.g., "Not Found", "Bad Request"). Subject to change without notice. Do not parse or rely on its content.
message
stringRequired
A readable explanation of the error. The wording can change without notice. Do not parse this field.
POST
/api/alerting/v2/action_policies/{id}/_disable
{
"created_at": "2026-01-15T12:00:00.000Z",
"created_by": {
"profile_uid": "u_elastic_0"
},
"description": "Sends notifications for alerts generated by rules with the production tag.",
"destinations": [
{
"id": "workflow-1",
"type": "workflow"
}
],
"enabled": false,
"group_by": null,
"grouping_mode": "per_alert",
"id": "action-policy-1",
"matcher": {
"tags": [
"production"
]
},
"name": "Notify on production alerts",
"snoozed_until": null,
"throttle": {
"interval": null,
"strategy": "on_status_change"
},
"updated_at": "2026-01-15T12:00:00.000Z",
"updated_by": {
"profile_uid": "u_elastic_0"
}
}
Response examples (400)
{
"code": "BAD_REQUEST",
"details": {
"errors": {
"errors": [],
"properties": {
"page": {
"errors": [
"Too small: expected number to be >=1"
]
}
}
}
},
"error": "Bad Request",
"message": "page: Too small: expected number to be >=1"
}
Response examples (401)
{
"code": "UNAUTHORIZED",
"error": "Unauthorized",
"message": "Authentication required to access this API."
}
Response examples (403)
{
"code": "FORBIDDEN",
"error": "Forbidden",
"message": "The current user does not have the required privileges for this request."
}
Response examples (404)
{
"code": "ACTION_POLICY_NOT_FOUND",
"details": {
"action_policy_id": "action-policy-1"
},
"error": "Not Found",
"message": "Action policy with ID \"action-policy-1\" not found"
}
Response examples (409)
{
"code": "ACTION_POLICY_VERSION_CONFLICT",
"details": {
"action_policy_id": "action-policy-1"
},
"error": "Conflict",
"message": "Action policy with ID \"action-policy-1\" has already been updated by another user"
}