stack kb alerting-v2 get-alerting-v2-execution-history-action-policies cli command
Auth required
Idempotent
Scope: global
elastic stack kb alerting-v2 get-alerting-v2-execution-history-action-policies \
[options]
List action policy executions
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--pagenumber- Page number (1-indexed). Defaults to 1.
--per-pagenumber- Number of events per page. Defaults to 20. Pass 0 for a count-only read.
--start-datestring- Inclusive ISO datetime lower bound on the event timestamp; overrides the default 24-hour window. Independent of episode_ids — e.g. set it to an episode’s start time to scope results to that episode’s lifetime.
--episode-idsstring[]-
Episode filter. Narrows events to those referencing at least one of the provided episode ids.
Repeatable: pass
--episode-idsmultiple times to supply more than one value --searchstring- Free-text search. Matches policy name, rule name, policy/rule ID (case-insensitive).
--rule-idsstring[]-
Explicit rule filter. Narrows events to those referencing at least one of the provided rule ids. Also unions with the search filter if both are provided.
Repeatable: pass
--rule-idsmultiple times to supply more than one value --outcomestring[]-
Outcome filter. When omitted matches all outcomes. Pass one or more of "dispatched", "throttled", "dispatch_failed" to narrow.
Repeatable: pass
--outcomemultiple times to supply more than one value --input-filestring- path to a JSON file to use as command input
--dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--json-
output as JSON