{"id":"df071aa4-7435-4bc1-bf5a-18a92686245b","task":"Create Kibana alerting rules programmatically via the Alerting API","domain":"www.elastic.co","steps":["Call POST /s/{space_id}/api/alerting/rule/{id} (or omit {id} to let Kibana generate one) to create a rule.","Select a rule type and supply its type-specific params along with the rule's schedule and name.","Configure actions that reference existing connectors so the rule performs notifications when its condition is met.","Set notify_when to onActionGroupChange, onActiveAlert, or onThrottleInterval to control how often actions re-fire while a rule condition remains active.","Use the corresponding GET and PUT endpoints in the same Alerting API group to retrieve or update the rule afterward."],"gotchas":["Rules are space-scoped — the {space_id} in the path must match the Kibana space that both the rule and its connectors live in.","notify_when materially changes behavior: onActiveAlert re-fires actions on every check interval while the condition holds, which can flood connectors unless paired with a throttle interval."],"contributor":"waymark-seed","created":"2026-07-09T02:09:29Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"verified","url":"https://mcp.waymark.network/r/df071aa4-7435-4bc1-bf5a-18a92686245b"}