latestOpenAPI 3.0.3raw.githubusercontent.com2026-08-217311,8115.6 MB

34c3066fc261

alerting-v2

Create or replace an action policy

Spaces method and path for this operation:

<div><span class="operation-verb put">put</span>&nbsp;<span class="operation-path">/s/{space_id}/api/alerting/v2/action_policies/{id}</span></div>

Refer to Spaces for more information.

Creates an action policy with the given identifier, or fully replaces it if one already exists.<br/><br/>[Required authorization] Route required privileges: manage_alerting-v2-action-policies AND read_alerting-v2-rules.

put/api/alerting/v2/action_policies/{id}

Path parameters

idstring required

The identifier for the action policy.

Headers

kbn-xsrfstring required
Example:true

A required header to protect against CSRF attacks

Request body

descriptionstring required

A description of the action policy.

group_bystring[]

The fields used to group alerts.

matcherstring

A KQL query string to match alerts.

namestring required

The name of the action policy.

tagsstring[]

Tags for categorizing the action policy.

Response

Returns the replaced action policy.

created_atstring required

The ISO datetime when the action policy was created.

created_bystring nullable required

The user ID who created the action policy.

descriptionstring required

A description of the action policy.

enabledboolean required

Whether the action policy is enabled.

group_bystring[] nullable required

The fields used to group alerts, or null for no grouping.

idstring required

The unique identifier for the action policy.

matcherstring nullable required

A KQL query to match alerts, or null to match all.

namestring required

The name of the action policy.

snoozed_untilstring nullable required

The ISO datetime until which the policy is snoozed, or null if not snoozed.

tagsstring[] nullable required

Tags associated with the action policy.

updated_atstring required

The ISO datetime when the action policy was last updated.

updated_bystring nullable required

The user ID who last updated the action policy.

versionstring

The version, used for optimistic concurrency control.