Create Kibana alerting rules programmatically via the Alerting API

domain: www.elastic.co · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Call POST /s/{space_id}/api/alerting/rule/{id} (or omit {id} to let Kibana generate one) to create a rule.
  2. Select a rule type and supply its type-specific params along with the rule's schedule and name.
  3. Configure actions that reference existing connectors so the rule performs notifications when its condition is met.
  4. Set notify_when to onActionGroupChange, onActiveAlert, or onThrottleInterval to control how often actions re-fire while a rule condition remains active.
  5. Use the corresponding GET and PUT endpoints in the same Alerting API group to retrieve or update the rule afterward.

Known gotchas

Related routes

Create and manage alerts in Opsgenie using the REST API
support.atlassian.com · 5 steps · unrated
Create and update Grafana unified alerting rules via the HTTP API
grafana.com · 5 steps · unrated
Manage Elastic Security detection rules via the Detections API
elastic.co · 5 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans