Spaces method and path for this operation:
Refer to Spaces for more information.
Creates an action policy with the given identifier, or fully replaces it if one already exists.
[Required authorization] Route required privileges: manage_alerting-v2-action-policies AND read_alerting-v2-rules.
Path parameters
-
The ID of the action policy. Copy it from the response when you create a policy, fetch one policy, or fetch the policy list. Chosen at creation and permanent — it cannot be changed afterwards. Re-using the id of a deleted resource is allowed but discouraged: execution history, change history, and alert episodes recorded under that id are retained and are attributed to the new resource. Ids appear in URLs and logs, so keep them free of sensitive data.
Minimum length is
1, maximum length is150. Format should match the following pattern:^[a-zA-Z0-9_-]+$.
Body
-
A description of the action policy.
Maximum length is
1024. -
The list of destinations. At least one is required.
At least
1but not more than10elements. -
Whether the action policy is enabled. On create, defaults to
truewhen omitted. On replace, omitting this field preserves the existing enabled state; otherwise it becomes the new stored value. -
The fields used to group alerts.
Not more than
16elements. Minimum length of each is1, maximum length of each is256. -
Selects the alerts this policy applies to. Set
tagsto match alerts from rules with those routing tags. Setexpressionto a KQL query, which will be evaluated against each alert.
If you set bothtagsandexpression, an alert must match the tags and the expression for the policy to apply. Whenmatcherisnull, or when bothtagsandexpressionare empty, the policy applies to all alerts.Additional properties are NOT allowed.
-
The name of the action policy.
Minimum length is
1, maximum length is256. -
The throttle configuration for notifications.
Additional properties are NOT allowed.
Responses
-
Returns the replaced action policy.
-
Returns the newly created action policy.
-
Indicates an invalid schema or parameters.
-
Indicates the request was not authenticated.
-
Indicates the user does not have the required privileges, or the current license does not support action policies. Creating, updating, and enabling action policies requires an active Enterprise license.
-
Indicates the action policy was created or updated concurrently by another caller.
-
Indicates an unexpected server-side error.
-
Indicates the alerting engine is disabled by the
alerting:v2:enabledadvanced setting.
curl \
--request PUT 'https://<KIBANA_URL>/api/alerting/v2/action_policies/{id}' \
--header "Authorization: $API_KEY" \
--header "Content-Type: application/json" \
--header "kbn-xsrf: true" \
--data '{
"description": "Sends notifications for alerts generated by rules with the production tag.",
"destinations": [
{
"id": "workflow-1",
"type": "workflow"
}
],
"grouping_mode": "per_alert",
"matcher": {
"tags": [
"production"
]
},
"name": "Notify on production alerts",
"throttle": {
"strategy": "on_status_change"
}
}'
{
"description": "Sends notifications for alerts generated by rules with the production tag.",
"destinations": [
{
"id": "workflow-1",
"type": "workflow"
}
],
"grouping_mode": "per_alert",
"matcher": {
"tags": [
"production"
]
},
"name": "Notify on production alerts",
"throttle": {
"strategy": "on_status_change"
}
}
{
"created_at": "2026-01-15T12:00:00.000Z",
"created_by": {
"profile_uid": "u_elastic_0"
},
"description": "Sends notifications for alerts generated by rules with the production tag.",
"destinations": [
{
"id": "workflow-1",
"type": "workflow"
}
],
"enabled": true,
"group_by": null,
"grouping_mode": "per_alert",
"id": "action-policy-1",
"matcher": {
"tags": [
"production"
]
},
"name": "Notify on production alerts",
"snoozed_until": null,
"throttle": {
"interval": null,
"strategy": "on_status_change"
},
"updated_at": "2026-01-15T12:00:00.000Z",
"updated_by": {
"profile_uid": "u_elastic_0"
}
}
{
"created_at": "2026-01-15T12:00:00.000Z",
"created_by": {
"profile_uid": "u_elastic_0"
},
"description": "Sends notifications for alerts generated by rules with the production tag.",
"destinations": [
{
"id": "workflow-1",
"type": "workflow"
}
],
"enabled": true,
"group_by": null,
"grouping_mode": "per_alert",
"id": "action-policy-1",
"matcher": {
"tags": [
"production"
]
},
"name": "Notify on production alerts",
"snoozed_until": null,
"throttle": {
"interval": null,
"strategy": "on_status_change"
},
"updated_at": "2026-01-15T12:00:00.000Z",
"updated_by": {
"profile_uid": "u_elastic_0"
}
}
{
"code": "INVALID_ACTION_POLICY_DATA",
"details": {
"context": "upsert",
"errors": {
"errors": [],
"properties": {
"name": {
"errors": [
"Invalid input: expected string, received undefined"
]
}
}
}
},
"error": "Bad Request",
"message": "Error validating upsert action policy data - name: Invalid input: expected string, received undefined"
}
{
"code": "UNAUTHORIZED",
"error": "Unauthorized",
"message": "Authentication required to access this API."
}
{
"code": "ACTION_POLICY_LICENSE_NOT_SUPPORTED",
"details": {
"current_license": "basic",
"license_status": "active",
"required_license": "enterprise"
},
"error": "Forbidden",
"message": "Action policies require an active enterprise license"
}
{
"code": "FORBIDDEN",
"error": "Forbidden",
"message": "The current user does not have the required privileges for this request."
}
{
"code": "ACTION_POLICY_VERSION_CONFLICT",
"details": {
"action_policy_id": "action-policy-1"
},
"error": "Conflict",
"message": "Action policy with ID \"action-policy-1\" has already been updated by another user"
}
{
"code": "INTERNAL_SERVER_ERROR",
"error": "Internal Server Error",
"message": "An unexpected error occurred."
}
{
"code": "ALERTING_DISABLED",
"error": "Service Unavailable",
"message": "Alerting is disabled."
}