# Cant close alerts using the api

**URL:** <https://discuss.elastic.co/t/cant-close-alerts-using-the-api/388605>\
**Category:** Kibana\
**Created:** [July 22, 2026, 8:27am UTC](https://discuss.elastic.co/t/cant-close-alerts-using-the-api/388605 "2026-07-22T08:27:51Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shahar\_Argov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shahar_argov/32/147571_2.png) [@Shahar\_Argov](https://discuss.elastic.co/u/Shahar_Argov)\
**Post date:** [July 22, 2026, 8:27am UTC](https://discuss.elastic.co/t/cant-close-alerts-using-the-api/388605/1 "2026-07-22T08:27:51Z")

</div>

hi there,  
we are using kibana security alerts and came by an error.

we were trying to use the kibana api to close security alerts using workflow automation.

about 10 seconds after the run is started, we get the following message: "fetch error"  
the error doesn't contain any explanation regarding the error.

We have tried to use the url with script and got the same error.

when i use update document with the field workflow\_status: closed it does close the alert but doesnt remove the opened so we still see it in the alerts so we open the alert and close again.

we would love help regarding that 🙂

---

<div class="post-metadata">

**Author:** ![Rafa\_Silva](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rafa_silva/32/147814_2.png) [@Rafa\_Silva](https://discuss.elastic.co/u/Rafa_Silva)\
**Post date:** [July 26, 2026, 4:22am UTC](https://discuss.elastic.co/t/cant-close-alerts-using-the-api/388605/2 "2026-07-26T04:22:09Z")

</div>

Hi @Shahar_Argov,

Which Stack version are you on, and is the automation Elastic Workflows or an external tool? That helps narrow it down.

Two things in the meantime:

Use the API instead of updating the document. Direct writes to the alert indices aren’t the supported path:

```auto
POST /api/detection_engine/signals/status
{
  "signal_ids": ["<alert _id>"],
  "status": "closed"
}

```

> **[Set a detection alert status | Kibana API documentation](https://www.elastic.co/docs/api/doc/kibana/operation/operation-setalertsstatus)**
>
> Spaces method and path for this operation:
> post /s/{spaceid}/api/detectionengine/signals/status
> Refer to Spaces for more information.
> Set the status of one or more detectio...

For workflow status

The alert still showing as open is probably a field name issue. The Alerts page filters on\*\* kibana.alert.workflow\_status, **not a top-level** workflow\_status. \*\*Could you check one of those documents and see which field actually changed?

> **[Manage detection alerts | Elastic Docs](https://www.elastic.co/docs/solutions/security/detect-and-alert/manage-detection-alerts)**
>
> Filter, triage, and take actions on detection alerts from the Alerts page.
