Connect workflows to the experimental alerting system
Workflows are the delivery layer that defines what happens when the experimental alerting system takes an action, such as sending a message, calling a webhook, or triggering an automation. Workflows connect the alerting system to your incident-response tools.
This page covers how action policies drive workflow invocations at runtime, the available alert episode lifecycle triggers, and when to use each pathway.
The experimental alerting system connects to workflows through two pathways. Both require an alert episode.
- Action Policies - Action policies evaluate eligible alert episodes on a continuous schedule and invoke workflows based on match conditions and frequency settings.
- Alert episode lifecycle triggers - Workflows are invoked when a specific event occurs on an alert episode, such as when the alert episode is activated, assigned, or deactivated.
Kibana evaluates action policies against alert episodes on a continuous schedule and invokes a workflow when an alert episode meets a policy's conditions. After a rule runs, the system routes each alert episode through the eligibility, scope, and frequency gates before invoking a workflow. For the step-by-step evaluation sequence, refer to How the dispatcher evaluates action policies.
Lifecycle triggers are a type of event-driven trigger that start a workflow immediately when a specific event occurs on an alert episode, with no scheduling or gating.
When an alert episode is activated, or assigned, acknowledged, or snoozed, the experimental alerting system emits a named trigger event (such as alerting.episodeAssigned or alerting.episodeAcked) and any workflow attached to it runs immediately.
If you're unsure whether to use lifecycle triggers or action policies, the following table compares when each option is a good fit. Both can run different workflows simultaneously and coexist without conflict.
| Action policies | Lifecycle triggers | |
|---|---|---|
| How they run | Evaluate alert episodes on a continuous schedule | React immediately to a specific event |
| Frequency control | Apply eligibility, match condition, and frequency gates | Fire exactly once per event, no gates to configure |
| Best for | Recurring notifications and escalation logic that runs as long as a problem persists | One-shot automations, such as opening a ticket when an alert episode is assigned or posting a message when it's deactivated |
- Create and configure an action policy: Start routing alert episodes to workflows.
- About action policies: Understand how action policies gate alert episodes before invoking a workflow.