latestOpenAPI 3.0.3raw.githubusercontent.com2026-08-207311,8115.6 MB

c36ed1cbdbb5

alerting-v2

Create an action policy

Spaces method and path for this operation:

<div><span class="operation-verb post">post</span>&nbsp;<span class="operation-path">/s/{space_id}/api/alerting/v2/action_policies</span></div>

Refer to Spaces for more information.

Creates an action policy with a server-generated identifier. To create or replace an action policy with a client-supplied identifier, use PUT /api/alerting/v2/action_policies/.<br/><br/>[Required authorization] Route required privileges: manage_alerting-v2-action-policies AND read_alerting-v2-rules.

post/api/alerting/v2/action_policies

Headers

kbn-xsrfstring required
Example:true

A required header to protect against CSRF attacks

Request body

descriptionstring required

A description of the action policy.

group_bystring[]

The fields used to group alerts.

matcherstring

A KQL query string to match alerts.

namestring required

The name of the action policy.

tagsstring[]

Tags for categorizing the action policy.

Response

Returns the newly created action policy.

created_atstring required

The ISO datetime when the action policy was created.

created_bystring nullable required

The user ID who created the action policy.

descriptionstring required

A description of the action policy.

enabledboolean required

Whether the action policy is enabled.

group_bystring[] nullable required

The fields used to group alerts, or null for no grouping.

idstring required

The unique identifier for the action policy.

matcherstring nullable required

A KQL query to match alerts, or null to match all.

namestring required

The name of the action policy.

snoozed_untilstring nullable required

The ISO datetime until which the policy is snoozed, or null if not snoozed.

tagsstring[] nullable required

Tags associated with the action policy.

updated_atstring required

The ISO datetime when the action policy was last updated.

updated_bystring nullable required

The user ID who last updated the action policy.

versionstring

The version, used for optimistic concurrency control.