stack kb alerting-v2 patch-alerting-v2-action-policies-id cli command
Auth required
elastic stack kb alerting-v2 patch-alerting-v2-action-policies-id \
--id <id> \
--version <version> \
[options]
Partially update an action policy.
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--idstringrequired- The ID of the action policy. Copy it from the response when you create a policy, fetch one policy, or fetch the policy list. Chosen at creation and permanent — it cannot be changed afterwards. Re-using the id of a deleted resource is allowed but discouraged: execution history, change history, and alert episodes recorded under that id are retained and are attributed to the new resource. Ids appear in URLs and logs, so keep them free of sensitive data.
--versionstringrequired- The current version of the action policy, used for optimistic concurrency control.
--descriptionstring- A description of the action policy.
--destinationsstring[]-
The list of destinations. At least one is required.
Repeatable: pass
--destinationsmultiple times to supply more than one value --group-bystring[]-
The fields used to group alerts.
Repeatable: pass
--group-bymultiple times to supply more than one value --grouping-modestring- The grouping mode for alert notifications.
--matcherstring- Selects the alerts this policy applies to. Set
tagsto match alerts from rules with those tags. Setexpressionto a KQL query, which will be evaluated against each alert. <br/><br/> If you set bothtagsandexpression, an alert must match the tags and the expression for the policy to apply. Whenmatcherisnull, or when bothtagsandexpressionare empty, the policy applies to all alerts. <br/><br/> Updatingmatcherreplaces it entirely: to changetagswithout droppingexpression, resend the currentexpressionvalue. --namestring- The name of the action policy.
--throttlestring- The throttle configuration for notifications.
--input-filestring- path to a JSON file to use as command input
--dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--no-validate- skip input validation and send the request as-is
--output-fieldsstring- comma-separated list of fields to include in output (dot-notation supported)
--output-templatestring- Mustache-like template for custom text output (e.g. "{{id}}: {{name}}")
--json-
output as JSON