Elastic Stack (ELK Stack) Alerting V2 API

Alerting V2 is an ES|QL-first alerting API for managing rules, alert actions, and action policies. Use these endpoints to create and manage detection rules, act on alerts, and control when and how notifications are delivered. These APIs are experimental.

Operations 52

GET /api/alerting/v2/action_policies List action policies #
POST /api/alerting/v2/action_policies Create an action policy #
POST /api/alerting/v2/action_policies/_bulk_delete Delete action policies in bulk by ID #
POST /api/alerting/v2/action_policies/_bulk_disable Disable action policies in bulk by ID #
POST /api/alerting/v2/action_policies/_bulk_enable Enable action policies in bulk by ID #
POST /api/alerting/v2/action_policies/_bulk_snooze Snooze action policies in bulk by ID #
POST /api/alerting/v2/action_policies/_bulk_unsnooze Cancel snooze for action policies in bulk by ID #
POST /api/alerting/v2/action_policies/_bulk_update_api_key Rotate API keys for action policies in bulk by ID #
POST /api/alerting/v2/action_policies/_match_for_rule Match action policies for a rule #
DELETE /api/alerting/v2/action_policies/{id} Delete an action policy #
GET /api/alerting/v2/action_policies/{id} Get an action policy #
PATCH /api/alerting/v2/action_policies/{id} Partially update an action policy #
PUT /api/alerting/v2/action_policies/{id} Create or replace an action policy #
POST /api/alerting/v2/action_policies/{id}/_disable Disable an action policy #
POST /api/alerting/v2/action_policies/{id}/_enable Enable an action policy #
POST /api/alerting/v2/action_policies/{id}/_snooze Snooze an action policy #
POST /api/alerting/v2/action_policies/{id}/_unsnooze Unsnooze an action policy #
POST /api/alerting/v2/action_policies/{id}/_update_api_key Update an action policy API key #
GET /api/alerting/v2/action_policies/tags Get action policy tags #
POST /api/alerting/v2/alerts/_bulk_action Bulk create alert actions #
POST /api/alerting/v2/alerts/{group_hash}/_ack Acknowledge an alert #
POST /api/alerting/v2/alerts/{group_hash}/_activate Activate an alert #
POST /api/alerting/v2/alerts/{group_hash}/_assign Assign an alert to a user #
POST /api/alerting/v2/alerts/{group_hash}/_deactivate Deactivate an alert #
POST /api/alerting/v2/alerts/{group_hash}/_snooze Snooze an alert #
POST /api/alerting/v2/alerts/{group_hash}/_tag Add tags to an alert #
POST /api/alerting/v2/alerts/{group_hash}/_unack Unacknowledge an alert #
POST /api/alerting/v2/alerts/{group_hash}/_unsnooze Unsnooze an alert #
GET /api/alerting/v2/execution_history/action_policies List action policy executions #
GET /api/alerting/v2/execution_history/rules List rule executions #
GET /api/alerting/v2/rules List rules #
POST /api/alerting/v2/rules Create a rule #
POST /api/alerting/v2/rules/_bulk_delete Delete rules in bulk by ID #
POST /api/alerting/v2/rules/_bulk_disable Disable rules in bulk by ID #
POST /api/alerting/v2/rules/_bulk_enable Enable rules in bulk by ID #
POST /api/alerting/v2/rules/_bulk_get Get rules in bulk #
POST /api/alerting/v2/rules/_bulk_update_api_key Update the API key of rules in bulk by ID #
POST /api/alerting/v2/rules/_delete_by_query Delete rules matching a query (dry-run by default) #
POST /api/alerting/v2/rules/_disable_by_query Disable rules matching a query (dry-run by default) #
POST /api/alerting/v2/rules/_enable_by_query Enable rules matching a query (dry-run by default) #
POST /api/alerting/v2/rules/_update_api_key_by_query Update the API key of rules matching a query (dry-run by default) #
DELETE /api/alerting/v2/rules/{id} Delete a rule #
GET /api/alerting/v2/rules/{id} Get a rule #
PATCH /api/alerting/v2/rules/{id} Update a rule #
PUT /api/alerting/v2/rules/{id} Create or replace a rule #
POST /api/alerting/v2/rules/{id}/_disable Disable a rule #
POST /api/alerting/v2/rules/{id}/_enable Enable a rule #
POST /api/alerting/v2/rules/{id}/_run Run a rule now #
GET /api/alerting/v2/rules/{id}/history List rule change history #
GET /api/alerting/v2/rules/{id}/history/{eventId} Get a rule change-history event #
GET /api/alerting/v2/rules/tags Get rule tags #
GET /api/alerting/v2/suggestions/rule_event_fields Get matcher data fields suggestions #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/elk-stack-alerting-v2-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

elk-stack-alerting-v2-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  contact:
    name: Kibana Team
  description: The Kibana REST APIs enable you to manage resources such as connectors, data views, and saved objects.
  title: Kibana Alerting V2 API
  version: ''
  x-doc-license:
    name: Attribution-NonCommercial-NoDerivatives 4.0 International
    url: https://creativecommons.org/licenses/by-nc-nd/4.0/
  x-feedbackLink:
    label: Feedback
    url: https://github.com/elastic/docs-content/issues/new?assignees=&labels=feedback%2Ccommunity&projects=&template=api-feedback.yaml&title=%5BFeedback%5D%3A+
servers:
- url: https://{kibana_url}
  variables:
    kibana_url:
      default: localhost:5601
security:
- apiKeyAuth: []
- basicAuth: []
tags:


# --- truncated at 32 KB (359 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/elk-stack/refs/heads/main/openapi/elk-stack-alerting-v2-api-openapi.yml