﻿---
title: stack kb alerting-v2 put-alerting-v2-action-policies-id cli command
description: Create or replace an action policy Behaviour flags: --dry-run — validate all inputs and exit without performing any action 
url: https://www.elastic.co/elastic/docs-builder/docs/4302/reference/elastic-cli/cli/stack/kb/alerting-v2/put-alerting-v2-action-policies-id
applies_to:
  - Elastic Cloud Serverless: Preview
  - Elastic Stack: Preview
---

# stack kb alerting-v2 put-alerting-v2-action-policies-id cli command
<cli-modifiers>
</cli-modifiers>

```bash
elastic stack kb alerting-v2 put-alerting-v2-action-policies-id \
  --id <id> \
  --description <description> \
  --destinations <destinations> \
  --name <name> \
  [options]
```

Create or replace an action policy
**Behaviour flags:**
`--dry-run` — validate all inputs and exit without performing any action

## Options

<definitions>
  <definition term="--id string required">
    The ID of the action policy. Copy it from the response when you create a policy, fetch one policy, or fetch the policy list. Chosen at creation and permanent — it cannot be changed afterwards. Re-using the id of a deleted resource is allowed but discouraged: execution history, change history, and alert episodes recorded under that id are retained and are attributed to the new resource. Ids appear in URLs and logs, so keep them free of sensitive data.
  </definition>
  <definition term="--description string required">
    A description of the action policy.
  </definition>
  <definition term="--destinations string[] required">
    The list of destinations. At least one is required.
    **Repeatable:** pass `--destinations` multiple times to supply more than one value
  </definition>
  <definition term="--name string required">
    The name of the action policy.
  </definition>
  <definition term="--group-by string[]">
    The fields used to group alerts.
    **Repeatable:** pass `--group-by` multiple times to supply more than one value
  </definition>
  <definition term="--grouping-mode string">
    The grouping mode for alert notifications.
  </definition>
  <definition term="--matcher string">
    Selects the alerts this policy applies to. Set `tags` to match alerts from rules with those tags. Set `expression` to a KQL query, which will be evaluated against each alert. <br/><br/> If you set both `tags` and `expression`, an alert must match the tags and the expression for the policy to apply. When `matcher` is `null`, or when both `tags` and `expression` are empty, the policy applies to all alerts.
  </definition>
  <definition term="--throttle string">
    The throttle configuration for notifications.
  </definition>
  <definition term="--input-file string">
    path to a JSON file to use as command input
  </definition>
  <definition term="--dry-run">
    validate all inputs and exit without performing any action (preview changes without applying them)
  </definition>
  <definition term="--no-validate">
    skip input validation and send the request as-is
  </definition>
</definitions>


## Global Options

<definitions>
  <definition term="--output-fields string">
    comma-separated list of fields to include in output (dot-notation supported)
  </definition>
  <definition term="--output-template string">
    Mustache-like template for custom text output (e.g. "{{id}}: {{name}}")
  </definition>
  <definition term="--json">
    output as JSON
  </definition>
</definitions>