stack kb alerting-v2 post-alerting-v2-action-policies cli command
Auth required
elastic stack kb alerting-v2 post-alerting-v2-action-policies \
--description <description> \
--destinations <destinations> \
--name <name> \
[options]
Create an action policy
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--descriptionstringrequired- A description of the action policy.
--destinationsstring[]required-
The list of destinations. At least one is required.
Repeatable: pass
--destinationsmultiple times to supply more than one value --namestringrequired- The name of the action policy.
--group-bystring[]-
The fields used to group alerts.
Repeatable: pass
--group-bymultiple times to supply more than one value --grouping-modestring- The grouping mode for alert notifications.
--matcherstring- Selects the alerts this policy applies to. Set
tagsto match alerts from rules with those tags. Setexpressionto a KQL query, which will be evaluated against each alert. <br/><br/> If you set bothtagsandexpression, an alert must match the tags and the expression for the policy to apply. Whenmatcherisnull, or when bothtagsandexpressionare empty, the policy applies to all alerts. --throttlestring- The throttle configuration for notifications.
--input-filestring- path to a JSON file to use as command input
--dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--no-validate- skip input validation and send the request as-is
--output-fieldsstring- comma-separated list of fields to include in output (dot-notation supported)
--output-templatestring- Mustache-like template for custom text output (e.g. "{{id}}: {{name}}")
--json-
output as JSON